~ / rigs / 0xSteph / pentest-ai-agents

0xSteph/pentest-ai-agents

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.

↗ GitHub ★ 2,306 mit updated 2mo ago collection Claude Code Claude plugin
share on X
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
CONTEXT TAX · EVERY TURN
~3.1k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
0/5
No committed guardrails · details

Copy this rig

# review before running: this installs third-party code
$ npx degit 0xSteph/pentest-ai-agents/agents ./rig-pentest-ai-agents/agents
$ npx degit 0xSteph/pentest-ai-agents/commands ./rig-pentest-ai-agents/commands

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ curl -fsSL --create-dirs -o .claude/agents/_scope-guard.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/_scope-guard.md
$ curl -fsSL --create-dirs -o .claude/agents/ad-attacker.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/ad-attacker.md
$ curl -fsSL --create-dirs -o .claude/agents/ai-recon.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/ai-recon.md
$ curl -fsSL --create-dirs -o .claude/agents/api-security.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/api-security.md
$ curl -fsSL --create-dirs -o .claude/agents/attack-planner.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/attack-planner.md
$ curl -fsSL --create-dirs -o .claude/agents/bizlogic-hunter.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/bizlogic-hunter.md
$ curl -fsSL --create-dirs -o .claude/agents/bug-bounty.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/bug-bounty.md
$ curl -fsSL --create-dirs -o .claude/agents/c2-operator.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/c2-operator.md
$ curl -fsSL --create-dirs -o .claude/agents/cicd-redteam.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/cicd-redteam.md
$ curl -fsSL --create-dirs -o .claude/agents/cloud-security.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/cloud-security.md
$ curl -fsSL --create-dirs -o .claude/agents/code-auditor.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/code-auditor.md
$ curl -fsSL --create-dirs -o .claude/agents/compliance-mapper.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/compliance-mapper.md
$ curl -fsSL --create-dirs -o .claude/agents/container-breakout.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/container-breakout.md
$ curl -fsSL --create-dirs -o .claude/agents/credential-tester.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/credential-tester.md
$ curl -fsSL --create-dirs -o .claude/agents/crypto-analyzer.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/crypto-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/ctf-solver.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/ctf-solver.md
$ curl -fsSL --create-dirs -o .claude/agents/data-exfiltrator.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/data-exfiltrator.md
$ curl -fsSL --create-dirs -o .claude/agents/database-attacker.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/database-attacker.md
$ curl -fsSL --create-dirs -o .claude/agents/detection-engineer.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/detection-engineer.md
$ curl -fsSL --create-dirs -o .claude/agents/engagement-planner.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/engagement-planner.md
$ curl -fsSL --create-dirs -o .claude/agents/evasion-specialist.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/evasion-specialist.md
$ curl -fsSL --create-dirs -o .claude/agents/exploit-chainer.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/exploit-chainer.md
$ curl -fsSL --create-dirs -o .claude/agents/exploit-guide.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/exploit-guide.md
$ curl -fsSL --create-dirs -o .claude/agents/fix-verifier.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/fix-verifier.md
$ curl -fsSL --create-dirs -o .claude/agents/forensics-analyst.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/forensics-analyst.md
$ curl -fsSL --create-dirs -o .claude/agents/iot-pentester.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/iot-pentester.md
$ curl -fsSL --create-dirs -o .claude/agents/lateral-movement.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/lateral-movement.md
$ curl -fsSL --create-dirs -o .claude/agents/llm-redteam.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/llm-redteam.md
$ curl -fsSL --create-dirs -o .claude/agents/malware-analyst.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/malware-analyst.md
$ curl -fsSL --create-dirs -o .claude/agents/mobile-pentester.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/mobile-pentester.md
$ curl -fsSL --create-dirs -o .claude/agents/network-attacker.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/network-attacker.md
$ curl -fsSL --create-dirs -o .claude/agents/opsec-anonymizer.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/opsec-anonymizer.md
$ curl -fsSL --create-dirs -o .claude/agents/osint-collector.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/osint-collector.md
$ curl -fsSL --create-dirs -o .claude/agents/password-auditor.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/password-auditor.md
$ curl -fsSL --create-dirs -o .claude/agents/payload-crafter.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/payload-crafter.md
$ curl -fsSL --create-dirs -o .claude/agents/persistence-planner.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/persistence-planner.md
$ curl -fsSL --create-dirs -o .claude/agents/phishing-operator.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/phishing-operator.md
$ curl -fsSL --create-dirs -o .claude/agents/poc-validator.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/poc-validator.md
$ curl -fsSL --create-dirs -o .claude/agents/privesc-advisor.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/privesc-advisor.md
$ curl -fsSL --create-dirs -o .claude/agents/recon-advisor.md https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/agents/recon-advisor.md

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

Subagents (53)

_scope-guard—
ad-attacker
model: sonnet
>-
ai-recon
model: sonnet
Delegates to this agent when the user wants to map the AI attack surface of an authorized web application before validation — discovering AI/LLM API endpoints (including OpenAI-compatible APIs), enume
api-security
model: sonnet
Delegates to this agent when the user asks about API security testing, REST API attacks, GraphQL exploitation, OAuth/OIDC vulnerabilities, JWT attacks, API enumeration, or web service penetration test
attack-planner
model: sonnet
>-
bizlogic-hunter
model: sonnet
>-
bug-bounty
model: sonnet
>-
c2-operator
model: sonnet
Delegates to this agent when the user asks about command-and-control framework operations, Sliver/Mythic/Havoc/Cobalt Strike configuration, listener and beacon tuning, malleable C2 profiles, sleep and
cicd-redteam
model: sonnet
>-
cloud-security
model: sonnet
Delegates to this agent when the user asks about cloud security testing, AWS/Azure/GCP penetration testing, cloud misconfiguration analysis, IAM privilege escalation, container security, Kubernetes at
code-auditor
model: sonnet
Delegates to this agent when the user wants a secure-code review of application source — static analysis for injection, auth, secrets, deserialization, and OWASP issues; SAST tooling guidance (Semgrep
compliance-mapper
model: sonnet
Delegates to this agent when the user wants to map penetration-test findings to compliance frameworks — PCI DSS, NIST 800-53 / CSF, ISO 27001, CIS Controls, HIPAA, SOC 2 — produce control-gap analysis
container-breakout
model: sonnet
Delegates to this agent when the user asks about container escape, Docker breakout, Kubernetes pod escape, runc/containerd CVE exploitation, capability abuse, privileged container hunting, kubelet API
credential-tester
model: sonnet
>-
crypto-analyzer
model: sonnet
Delegates to this agent when the user wants to analyze cryptographic usage — weak algorithms or modes, key and IV/nonce management, TLS/certificate configuration, randomness quality, password hashing,
ctf-solver
model: sonnet
Delegates to this agent when the user is working on CTF challenges, capture the flag competitions, HackTheBox machines, TryHackMe rooms, or needs help with CTF methodology including web exploitation,
data-exfiltrator
model: sonnet
Delegates to this agent when the user wants to test exfiltration and DLP/egress controls during an authorized engagement — DNS tunneling, HTTPS/cloud-storage exfil, ICMP, protocol abuse, and staging —
database-attacker
model: sonnet
Delegates to this agent when the user wants database-specific offensive testing on an authorized target — SQL and NoSQL injection depth, authenticated database enumeration, DBMS privilege escalation,
detection-engineer
model: sonnet
Delegates to this agent when the user asks about detection rules, SIEM queries, threat hunting, indicator analysis, log analysis, blue team detection for specific attack techniques, or creating detect
engagement-planner
model: sonnet
Delegates to this agent when the user needs to plan a penetration test, define attack methodology, scope an engagement, map techniques to MITRE ATT&CK, or create a rules of engagement template.
evasion-specialist
model: sonnet
Delegates to this agent when the user wants to test defensive evasion during an authorized red team or EDR-validation engagement — AV/EDR evasion, AMSI and ETW bypass, payload obfuscation, in-memory e
exploit-chainer
model: sonnet
>-
exploit-guide
model: sonnet
Delegates to this agent when the user asks about exploitation techniques, attack methodologies, tool configurations for authorized testing, post-exploitation activities, or specific vulnerability expl
fix-verifier
model: sonnet
>-
forensics-analyst
model: sonnet
Delegates to this agent when the user asks about digital forensics, incident response, evidence acquisition, memory forensics, disk forensics, network forensics, timeline analysis, or chain of custody
iot-pentester
model: sonnet
Delegates to this agent when the user wants authorized security testing of IoT/embedded devices — firmware extraction and analysis, hardware interfaces (UART/JTAG/SPI), radio protocols (BLE/Zigbee/sub
lateral-movement
model: sonnet
Delegates to this agent when the user wants post-foothold lateral-movement strategy on an authorized engagement — pass-the-hash/ticket, remote execution (PsExec/WMI/WinRM/DCOM/SSH), <redacted>, RDP, a
llm-redteam
model: sonnet
Delegates to this agent when the user asks about LLM and AI system red teaming, prompt injection (direct and indirect), jailbreak techniques, RAG poisoning, model exfiltration, training data extractio
malware-analyst
model: sonnet
Delegates to this agent when the user asks about malware analysis, reverse engineering, binary analysis, disassembly, debugging, sandbox analysis, static analysis, dynamic analysis, or suspicious file
mobile-pentester
model: sonnet
Delegates to this agent when the user asks about mobile application security testing, Android pentesting, iOS pentesting, APK analysis, IPA analysis, mobile API testing, certificate pinning bypass, or
network-attacker
model: sonnet
Delegates to this agent when the user wants layer-2/layer-3 offensive testing on an authorized internal network — LLMNR/NBT-NS/mDNS poisoning, ARP spoofing and MITM, NTLM relay, IPv6/mitm6 takeover, V
opsec-anonymizer
model: sonnet
Delegates to this agent when the user asks about operator-side identity hygiene, source IP separation, traffic anonymization for authorized red team work, Tor and proxy chains, burner infrastructure p
osint-collector
model: sonnet
Delegates to this agent when the user asks about OSINT, reconnaissance, information gathering, target profiling, email harvesting, subdomain enumeration, social media recon, breach data, open source i
password-auditor
model: sonnet
Delegates to this agent when the user wants to audit password posture — policy review against NIST 800-63B, password-storage/hashing review, breach-exposure checks, and lockout-safe password-spray pla
payload-crafter
model: sonnet
Delegates to this agent when the user asks about generating offensive payloads, building shellcode, working with msfvenom, packing or encoding payloads, building reverse shells, creating EDR-test bina
persistence-planner
model: sonnet
Delegates to this agent when the user wants to plan and document persistence during an authorized red team engagement — host persistence (Windows/Linux), Active Directory persistence (golden/silver ti
phishing-operator
model: sonnet
Delegates to this agent when the user asks about setting up phishing infrastructure, configuring Evilginx3 or GoPhish, adversary-in-the-middle credential capture, MFA token relay, domain lookalike det
poc-validator
model: sonnet
>-
privesc-advisor
model: sonnet
Delegates to this agent when the user asks about privilege escalation techniques, local enumeration, Linux or Windows privilege escalation, container escape, or needs help escalating access on a compr
recon-advisor
model: sonnet
>-

Slash commands (3)

/agents-for/memory/recommend

Similar rigs

copied ✓