reverse-skill-router
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。
$ npx -y skills add zhaoxuya520/reverse-skill --skill pentest-tools --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/pentest-toolsContext preview
The summary Claude sees to decide when to auto-load this skill.
主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。
name: pentest-tools description: | 主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。
1. `NOW`: 读取 `../field-journal/precedent-pentest.md` — 确认本 skill 的操作是已授权的常规操作 2. `NOW`: 确认 **scope.md** 存在且 `auth.status=granted`、`network_profile` 合法(`../ops/scope-contract.md`)。缺 scope 则跑 `case-init.ps1` 并停到用户给授权;**禁止**自动加 `-AuthGranted` 3. `NOW`: 确认当前任务是否命中本 skill 的适用范围 4. `NEXT`: 读取 `../tool-index.md`,校验工具可用性和实际路径 5. `NEXT`: 缺工具时调用 bootstrap,不要猜路径 6. `ACT`: 侦察阶段优先 `references/recon-pipeline.md`(CF 浏览器头 / Windows nmap / curl `--globoff`);每批结果追加 `timeline.md`;候选用 `../scripts/append-evidence.ps1` 写入 Evidence(命中≠已验证) 7. `ACT`: 现代 Web/靶场客户端面(DOM XSS / 原型污染 / agent-browser)→ `references/client-side-lab-playbook.md`;未打穿也要写 observed Evidence + 失败门闩
当任务属于以下场景时使用本 skill:
| 场景 | 用什么 | |------|--------| | 主动扫描/攻击(Nmap/Nuclei/SQLMap) | **本 skill** | | 逆向分析二进制 | `ida-reverse/` 或 `radare2/` | | 前端 JS 签名逆向 | `js-reverse/` | | 浏览器/桌面自动化操作 | `browser-automation/` | | CTF 竞赛(综合) | `CTF-Sandbox-Orchestrator/` |
简单判断:
---
| 工具 | 用途 | 典型命令 | |------|------|---------| | **Nmap** | 端口扫描、服务识别、OS 检测 | `nmap -sV -sC -O target` | | **Masscan** | 大规模快速端口扫描 | `masscan -p1-65535 target --rate=1000` | | **Subfinder** | 子域名枚举 | `subfinder -d target.com` | | **httpx** | HTTP 探测、存活检测 | `httpx -l urls.txt -status-code` |
| 工具 | 用途 | 典型命令 | |------|------|---------| | **Nuclei** | 模板化漏洞扫描(CVE/配置/暴露) | `nuclei -u target -t cves/` | | **ZAP** | Web 应用安全扫描 | 通过 API 或 MCP 调用 | | **Nikto** | Web 服务器漏洞扫描 | `nikto -h target` |
| 工具 | 用途 | 典型命令 | |------|------|---------| | **SQLMap** | SQL 注入自动化 | `sqlmap -u "url?id=1" --batch --dbs` | | **FFUF** | 目录/参数爆破 | `ffuf -u target/FUZZ -w wordlist.txt` | | **Gobuster** | 目录/子域名爆破 | `gobuster dir -u target -w wordlist` | | **XSStrike** | XSS 检测 | `xsstrike -u "url?param=test"` |
| 工具 | 用途 | 典型命令 | |------|------|---------| | **Hashcat** | GPU 哈希破解 | `hashcat -m 0 hash.txt wordlist.txt` | | **John the Ripper** | CPU 哈希破解 | `john --wordlist=rockyou.txt hash.txt` | | **Hydra** | 在线暴力破解 | `hydra -l admin -P pass.txt target ssh` |
| 工具 | 用途 | 说明 | |------|------|------| | **Metasploit** | 漏洞利用框架 | 需要单独安装,体量大 | | **Impacket** | Windows 协议利用(SMB/WMI/Kerberos) | `pip install impacket` |
---
本 skill 支持两种 MCP 后端,选一个即可:
# 拉取并运行 docker pull ramkansal/pentestmcp docker run -d -p 8080:8080 ramkansal/pentestmcp # 或本地构建 git clone https://github.com/ramkansal/pentestmcp.git cd pentestmcp docker build -t pentestmcp . docker run -d -p 8080:8080 pentestmcp
{
"mcpServers": {
"pentest": {
"url": "http://localhost:8080/mcp"
}
}
}如果只需要某一个工具:
| 工具 | MCP 项目 | 安装 | |------|---------|------| | Nmap | [nmap-mcp-server](https://github.com/PhialsBasement/nmap-mcp-server) | npm | | Nuclei | [nuclei-mcp](https://github.com/addcontent/nuclei-mcp) | npm | | SQLMap | mcp-security-hub 子模块 | pip |
Reqable 桌面客户端可通过官方 [Reqable MCP Server](https://github.com/reqable/reqable-mcp-server) 暴露本地抓包、API、断点和规则能力。先单独安装并启动 Reqable,再登记 MCP:
powershell -NoProfile -ExecutionPolicy Bypass -File skills\scripts\bootstrap-reverse.ps1 -Capability reqable-mcp -McpHostTarget Codex
将 `Codex` 替换为 `Claude` 或 `Both` 可选择对应客户端;省略 `-McpHostTarget` 时不会写任何客户端全局配置。
登记后的 stdio 配置为:
{
"mcpServers": {
"reqable-mcp": {
"command": "npx",
"args": ["-y", "reqable-mcp-server@1.0.1", "--scope", "minimal"]
}
}
}---
> **重要**:执行渗透测试时,必须按 `references/pentest-loop.md` 的自主循环框架运行。 > 该框架定义了完整的风险门控、记录规范、上下文压缩和完成检查机制。
1. 信息收集 - Nmap 端口扫描 → 确认开放服务 - Subfinder 子域名枚举 → 扩大攻击面 - httpx 存活检测 → 过滤有效目标 2. 漏洞扫描 - Nuclei 模板扫描 → 快速发现已知漏洞 - ZAP/Nikto → Web 应用深度扫描 3. 漏洞利用 - SQLMap → SQL 注入 - FFUF → 发现隐藏路径/参数 - 手动验证 → 确认可利用性 4. 后渗透(如果授权范围内) - 权限提升 - 横向移动 - 数据提取 5. 报告 - 调用 docs-generator skill 生成渗透测试报告
1. nmap -sV -sC target → 端口+服务 2. nuclei -u target -severity critical,high → 高危漏洞 3. 有 Web 服务 → ffuf -u target/FUZZ -w common.txt → 目录 4. 汇总发现 → 决定下一步
---
---
| 工具 | 可自动安装 | 安装方式 | 说明 | |------|-----------|---------|------| | Nmap | ✓ | winget (`Insecure.Nmap`) | Windows 版 | | Nuclei | ✓ | `go install` 或 GitHub Release | 需要 Go 或直接下载二进制 | | SQLMap | ✓ | `pip install sqlmap` 或 git clone | Python | | FFUF | ✓ | GitHub Release | Go 二进制 | | SecLists | ✓ | GitHub Release ZIP | 字典大全(FFUF/Gobuster 必备) | | Hashcat | ✗ | 手动下载 | 需要 GPU 驱动 | | Metasploit | ✗ | 手动安装 | 体量大,建议用 Kali | | pentestMCP (Docker) | ✗ | 需要 Docker | `docker run ramkansal/pentestmcp` | | Impacket | ✓ | `pip i
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Repo: zhaoxuya520/reverse-skill
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including…
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native…
Use for authorized multi-stage attack-path planning and orchestration when a task spans…
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection,…