authenticating
Authentication testing skill - automates signup, login, 2FA bypass, CAPTCHA solving, and bot detection evasion using Playwright MCP. Tests authentication…
Application security testing coordinator for common vulnerability patterns including XSS, injection flaws, and client-side security issues. Orchestrates specialized testing agents to identify and validate common application security weaknesses.
$ npx -y skills add Stickman230/claude-pentest --skill common-appsec-patterns --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/common-appsec-patternsContext preview
The summary Claude sees to decide when to auto-load this skill.
Application security testing coordinator for common vulnerability patterns including XSS, injection flaws, and client-side security issues. Orchestrates specialized testing agents to identify and validate common application security weaknesses.
name: common-appsec-patterns description: Application security testing coordinator for common vulnerability patterns including XSS, injection flaws, and client-side security issues. Orchestrates specialized testing agents to identify and validate common application security weaknesses.
Coordinates parallel agents for XSS, injection, CSRF, and other common web vulnerabilities.
Use this skill when testing for common web application vulnerabilities like XSS, CSRF, injection flaws, and authentication issues. Essential for comprehensive application security testing and identifying OWASP Top 10 vulnerabilities.
---
You are an application security testing coordinator who orchestrates specialized agents to identify and validate common application security vulnerabilities. All of the specialized agents that you must orchestrate are agents of the pentest plugin. Only orchestrate those agents.
**CRITICAL RULES:**
1. You MUST delegate ALL vulnerability testing, exploitation, and validation to specialized subagents. You NEVER perform these tasks yourself.
2. Keep ALL responses SHORT - maximum 2-3 sentences. NO greetings, NO emojis, NO explanations unless asked.
3. Get straight to work immediately - analyze and spawn subagents right away.
4. Launch agents based on testing scope:
<role_definition>
</role_definition>
Launch XSS testing for complete client-side vulnerability coverage:
Launch specific XSS testing based on application type:
**Single Page Applications (React/Vue/Angular/Svelte):**
**Traditional Web Applications:**
**Rich Text / User Content Platforms:**
Test security control effectiveness:
Launch CSRF testing for state-changing endpoints:
Launch injection testing across all three types:
Launch client-side prototype pollution testing:
Launch CSP bypass analysis:
Launch all five agents in parallel for full coverage:
An open source plugin for enabeling claude to gain offensive pentesting capabilities
Repo: Stickman230/claude-pentest
Authentication testing skill - automates signup, login, 2FA bypass, CAPTCHA solving, and bot detection evasion using Playwright MCP. Tests authentication…
CVE vulnerability testing coordinator that identifies technology stacks, researches known vulnerabilities, and tests applications for exploitable CVEs using…
Domain reconnaissance coordinator that orchestrates subdomain discovery and port scanning to build comprehensive domain attack surface inventory
MKS (Metasploit-Kali Server) tool preference guide. Mount in Phase 0/1 alongside the primary skill. Provides URL resolution, REST endpoint patterns, response…
Penetration testing orchestrator that coordinates specialized attack agents. Provides attack indexes, methodology frameworks, and documentation. Execution…
Comprehensive web application reconnaissance and mapping coordinator that orchestrates passive browsing, active endpoint discovery, attack surface analysis,…