Stickman230/claude-pentest
An open source plugin for enabeling claude to gain offensive pentesting capabilities
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
Copy this rig
$ git clone --depth 1 https://github.com/Stickman230/claude-pentest MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit Stickman230/claude-pentest/plugins/pentest/skills/authenticating .claude/skills/authenticating $ npx degit Stickman230/claude-pentest/plugins/pentest/skills/common-appsec-patterns .claude/skills/common-appsec-patterns $ npx degit Stickman230/claude-pentest/plugins/pentest/skills/cve-testing .claude/skills/cve-testing $ npx degit Stickman230/claude-pentest/plugins/pentest/skills/domain-assessment .claude/skills/domain-assessment $ npx degit Stickman230/claude-pentest/plugins/pentest/skills/mks .claude/skills/mks $ npx degit Stickman230/claude-pentest/plugins/pentest/skills/pentest .claude/skills/pentest $ npx degit Stickman230/claude-pentest/plugins/pentest/skills/web-application-mapping .claude/skills/web-application-mapping
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 6,974 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(~/.aws/**)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(.env)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/.env.*)",
"Read(**/*.key)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(npm publish:*)",
"Bash(wget *)",
"Bash(git rebase *)",
"Bash(gh pr merge *)",
"Bash(git commit *)"
]
}
} Skills (7)
Similar rigs
leandronsp/dotfiles
My dotfiles
Orchestrator 8.8k tok ·
greglas75/zuvo
Auto-activating, multi-agent skill ecosystem for Claude Code, Codex, and Cursor. 51 skills, 26 agents, quality gates, knowledge store, adversarial review, content writing & optimization.
Skill Collector 8.7k tok ·
HoangNguyen0403/agent-skills-standard
A collection of Agent Skills Standard and Best Practice for Programming Languages, Frameworks that help our AI Agent follow best practies on frameworks and programming laguages
Orchestrator 8.0k tok ·
Houseofmvps/ultraship
"ULTRASHIP" Claude Code plugin — 39 skills, 33 tools, 11 agents for ship-ready workflows: planning, review, pentesting, safety guardrails, canary monitoring, SEO/AI-readiness check, penetration testing, code review, competitive analysis, in
Orchestrator 14.3k tok ·