本文へ移動
cccskills
無料GitHub で公開

pentest-tools

主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。

インストール方法を見る

含まれるファイル(16)

  • SKILL.md6.2 KB
  • references/ai-pentest-agents.md6.0 KB
  • references/ai-pentesting-landscape-2026.md3.4 KB
  • references/automation-loop-pattern.md5.2 KB
  • references/awesome-pentest-digest.md5.9 KB
  • references/burpsuite-mcp-guide.md23.0 KB
  • references/kali-mcp-ecosystem.md4.4 KB
  • references/nuclei-guide-2026.md4.0 KB
  • references/pentest-ai-agents-matrix.md5.0 KB
  • references/pentest-loop.md6.6 KB
  • references/recon-pipeline.md5.7 KB
  • templates/findings.md328 B
  • templates/progress.md242 B
  • templates/rules.md722 B
  • templates/scope.md422 B
  • templates/task_plan.md543 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

渗透测试工具链 (Pentest Tools)

适用范围

当任务属于以下场景时使用本 skill:

  • 目标信息收集(端口扫描、子域名枚举、服务识别)
  • 漏洞扫描(Web 漏洞、CVE 检测、配置错误)
  • Web 渗透(SQL 注入、XSS、SSRF、目录爆破)
  • 密码破解(哈希破解、字典攻击)
  • 网络渗透(服务利用、横向移动辅助)

与其他 skill 的分工

场景用什么
主动扫描/攻击(Nmap/Nuclei/SQLMap)本 skill
逆向分析二进制ida-reverse/ 或 radare2/
前端 JS 签名逆向js-reverse/
浏览器/桌面自动化操作browser-automation/
CTF 竞赛(综合)CTF-Sandbox-Orchestrator/

简单判断:

  • 需要"扫描目标、发现漏洞、利用漏洞" → 本 skill
  • 需要"分析程序内部逻辑" → 逆向类 skill
  • 需要"操作浏览器/桌面" → browser-automation

工具矩阵

信息收集

工具用途典型命令
Nmap端口扫描、服务识别、OS 检测nmap -sV -sC -O target
Masscan大规模快速端口扫描masscan -p1-65535 target --rate=1000
Subfinder子域名枚举subfinder -d target.com
httpxHTTP 探测、存活检测httpx -l urls.txt -status-code

漏洞扫描

工具用途典型命令
Nuclei模板化漏洞扫描(CVE/配置/暴露)nuclei -u target -t cves/
ZAPWeb 应用安全扫描通过 API 或 MCP 调用
NiktoWeb 服务器漏洞扫描nikto -h target

Web 渗透

工具用途典型命令
SQLMapSQL 注入自动化sqlmap -u "url?id=1" --batch --dbs
FFUF目录/参数爆破ffuf -u target/FUZZ -w wordlist.txt
Gobuster目录/子域名爆破gobuster dir -u target -w wordlist
XSStrikeXSS 检测xsstrike -u "url?param=test"

密码破解

工具用途典型命令
HashcatGPU 哈希破解hashcat -m 0 hash.txt wordlist.txt
John the RipperCPU 哈希破解john --wordlist=rockyou.txt hash.txt
Hydra在线暴力破解hydra -l admin -P pass.txt target ssh

利用框架

工具用途说明
Metasploit漏洞利用框架需要单独安装,体量大
ImpacketWindows 协议利用(SMB/WMI/Kerberos)pip install impacket

工作流

标准渗透流程

重要:执行渗透测试时,必须按 references/pentest-loop.md 的自主循环框架运行。 该框架定义了完整的风险门控、记录规范、上下文压缩和完成检查机制。

1. 信息收集
   - Nmap 端口扫描 → 确认开放服务
   - Subfinder 子域名枚举 → 扩大攻击面
   - httpx 存活检测 → 过滤有效目标

2. 漏洞扫描
   - Nuclei 模板扫描 → 快速发现已知漏洞
   - ZAP/Nikto → Web 应用深度扫描

3. 漏洞利用
   - SQLMap → SQL 注入
   - FFUF → 发现隐藏路径/参数
   - 手动验证 → 确认可利用性

4. 后渗透(如果授权范围内)
   - 权限提升
   - 横向移动
   - 数据提取

5. 报告
   - 调用 docs-generator skill 生成渗透测试报告

快速扫描流程(5 分钟出结果)

1. nmap -sV -sC target → 端口+服务
2. nuclei -u target -severity critical,high → 高危漏洞
3. 有 Web 服务 → ffuf -u target/FUZZ -w common.txt → 目录
4. 汇总发现 → 决定下一步

注意事项

  • 必须有授权 — 所有扫描/攻击操作必须在授权范围内
  • 控制扫描速率 — 避免触发 WAF/IDS 或打崩目标
  • 先被动后主动 — 先信息收集,再漏洞扫描,最后利用
  • 记录所有操作 — 每个命令和结果都要记录,用于报告
  • 不要盲目自动化 — AI 应该在每个关键步骤等待确认

参考资源

本 skill 内参考文档

  • references/pentest-loop.md — 核心循环框架(风险门控 + 记录规范 + 上下文压缩)
  • references/recon-pipeline.md — 授权侦察流水线(CF 头 / nmap / Evidence)
  • references/client-side-lab-playbook.md — DOM XSS / 原型污染 / agent-browser(靶场客户端面)
  • references/burpsuite-mcp-guide.md — BurpSuite MCP 完整指南(63 工具 + 7 大使用场景 + AI Prompt 模板)
  • references/automation-loop-pattern.md — 自动化循环测试模式(轻量版)
  • references/awesome-pentest-digest.md — 渗透工具精华速查
  • references/pentest-ai-agents-matrix.md — 35 agent 覆盖矩阵
  • payloads/ — 自定义 payload 目录(AI 优先使用)
  • templates/ — 渗透测试必需文件模板(scope/rules/plan/findings/progress)

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Train and optimize AI agents using Microsoft's Agent Lightning framework with reinforcement learning. Use when setting up agent training, instrumenting agents with tracing, configuring LightningStore, implementing reward functions, or optimizing prompts with RL/APO algorithms.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5322026年10月10日 更新

Post-run self-evaluation system that scores agent output on correctness, clarity, actionability, and conciseness. Use after /team runs, skill executions, or when explicitly asked to evaluate output quality.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5322026年10月10日 更新

Create AI marketing videos for ads, promos, product launches, and brand content. Models: Veo, Seedance, Wan, FLUX for visuals, Kokoro for voiceover. Types: product demos, testimonials, explainers, social ads, brand videos. Use for: Facebook ads, YouTube ads, product launches, brand awareness. Triggers: marketing video, ad video, promo video, commercial, brand video, product video, explainer video, ad creative, video ad, facebook ad video, youtube ad, instagram ad, tiktok ad, promotional video, launch video

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5322026年10月10日 更新

Use when building AI features into a product: LLM integration, RAG pipelines, guardrails, streaming, AI UX, prompt engineering, or AI cost control. Treats prompts as code and validates every model output.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5322026年10月10日 更新

Your AI research and engineering brain trust. 59 named personas across 8 cells covering frontier labs, applied product, model architecture, reasoning/RL/agents, alignment and interpretability, theory and science of DL, multimodal and…

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5322026年10月10日 更新

Use when designing a new REST or GraphQL API, reviewing an API spec before implementation, setting team API standards, or migrating REST to GraphQL. Covers resources, HTTP semantics, pagination, error handling, and pitfalls.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5322026年10月10日 更新

coco-research のスキルをすべて見る

このスキルの問題を報告する