Back to skills
SKILL.md
Pentest Tools
ASecurity主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。
- 434 stars
- 0 votes
- 0 copies
- 0 views
- Added September 23, 2026
Works with
Security analysis
92/100- Installs packages at runtime which could introduce malicious dependencies
Pro scans all 16 files and shows the line behind each finding
npx -y skills add coco-research/coco --skill pentest-tools --agent claude-codeAre you the author of Pentest Tools?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/coco-research-pentest-tools)---
name: pentest-tools
description: |
主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。
通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。
触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。
user-invocable: true
---
# 渗透测试工具链 (Pentest Tools)
## 适用范围
当任务属于以下场景时使用本 skill:
- 目标信息收集(端口扫描、子域名枚举、服务识别)
- 漏洞扫描(Web 漏洞、CVE 检测、配置错误)
- Web 渗透(SQL 注入、XSS、SSRF、目录爆破)
- 密码破解(哈希破解、字典攻击)
- 网络渗透(服务利用、横向移动辅助)
### 与其他 skill 的分工
| 场景 | 用什么 |
|------|--------|
| 主动扫描/攻击(Nmap/Nuclei/SQLMap) | **本 skill** |
| 逆向分析二进制 | `ida-reverse/` 或 `radare2/` |
| 前端 JS 签名逆向 | `js-reverse/` |
| 浏览器/桌面自动化操作 | `browser-automation/` |
| CTF 竞赛(综合) | `CTF-Sandbox-Orchestrator/` |
简单判断:
- 需要"扫描目标、发现漏洞、利用漏洞" → 本 skill
- 需要"分析程序内部逻辑" → 逆向类 skill
- 需要"操作浏览器/桌面" → browser-automation
---
## 工具矩阵
### 信息收集
| 工具 | 用途 | 典型命令 |
|------|------|---------|
| **Nmap** | 端口扫描、服务识别、OS 检测 | `nmap -sV -sC -O target` |
| **Masscan** | 大规模快速端口扫描 | `masscan -p1-65535 target --rate=1000` |
| **Subfinder** | 子域名枚举 | `subfinder -d target.com` |
| **httpx** | HTTP 探测、存活检测 | `httpx -l urls.txt -status-code` |
### 漏洞扫描
| 工具 | 用途 | 典型命令 |
|------|------|---------|
| **Nuclei** | 模板化漏洞扫描(CVE/配置/暴露) | `nuclei -u target -t cves/` |
| **ZAP** | Web 应用安全扫描 | 通过 API 或 MCP 调用 |
| **Nikto** | Web 服务器漏洞扫描 | `nikto -h target` |
### Web 渗透
| 工具 | 用途 | 典型命令 |
|------|------|---------|
| **SQLMap** | SQL 注入自动化 | `sqlmap -u "url?id=1" --batch --dbs` |
| **FFUF** | 目录/参数爆破 | `ffuf -u target/FUZZ -w wordlist.txt` |
| **Gobuster** | 目录/子域名爆破 | `gobuster dir -u target -w wordlist` |
| **XSStrike** | XSS 检测 | `xsstrike -u "url?param=test"` |
### 密码破解
| 工具 | 用途 | 典型命令 |
|------|------|---------|
| **Hashcat** | GPU 哈希破解 | `hashcat -m 0 hash.txt wordlist.txt` |
| **John the Ripper** | CPU 哈希破解 | `john --wordlist=rockyou.txt hash.txt` |
| **Hydra** | 在线暴力破解 | `hydra -l admin -P pass.txt target ssh` |
### 利用框架
| 工具 | 用途 | 说明 |
|------|------|------|
| **Metasploit** | 漏洞利用框架 | 需要单独安装,体量大 |
| **Impacket** | Windows 协议利用(SMB/WMI/Kerberos) | `pip install impacket` |
---
## 工作流
### 标准渗透流程
> **重要**:执行渗透测试时,必须按 `references/pentest-loop.md` 的自主循环框架运行。
> 该框架定义了完整的风险门控、记录规范、上下文压缩和完成检查机制。
```text
1. 信息收集
- Nmap 端口扫描 → 确认开放服务
- Subfinder 子域名枚举 → 扩大攻击面
- httpx 存活检测 → 过滤有效目标
2. 漏洞扫描
- Nuclei 模板扫描 → 快速发现已知漏洞
- ZAP/Nikto → Web 应用深度扫描
3. 漏洞利用
- SQLMap → SQL 注入
- FFUF → 发现隐藏路径/参数
- 手动验证 → 确认可利用性
4. 后渗透(如果授权范围内)
- 权限提升
- 横向移动
- 数据提取
5. 报告
- 调用 docs-generator skill 生成渗透测试报告
```
### 快速扫描流程(5 分钟出结果)
```text
1. nmap -sV -sC target → 端口+服务
2. nuclei -u target -severity critical,high → 高危漏洞
3. 有 Web 服务 → ffuf -u target/FUZZ -w common.txt → 目录
4. 汇总发现 → 决定下一步
```
---
## 注意事项
- **必须有授权** — 所有扫描/攻击操作必须在授权范围内
- **控制扫描速率** — 避免触发 WAF/IDS 或打崩目标
- **先被动后主动** — 先信息收集,再漏洞扫描,最后利用
- **记录所有操作** — 每个命令和结果都要记录,用于报告
- **不要盲目自动化** — AI 应该在每个关键步骤等待确认
---
## 参考资源
- [awesome-pentest](https://github.com/enaqx/awesome-pentest) — 25k+ stars 渗透工具大全
- [SecLists](https://github.com/danielmiessler/SecLists) — 字典/payload 集合(FFUF/Gobuster 必备)
- [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings) — 各类漏洞 payload
- [HackTricks](https://book.hacktricks.wiki/) — 渗透技巧百科
- [pentest-ai-agents](https://github.com/0xSteph/pentest-ai-agents) — 35 个 Claude Code 渗透子 agent(参考其 prompt 模式)
- [Pentest Swarm AI](https://github.com/Armur-Ai/Pentest-Swarm-AI) — 群体智能自主渗透框架(多 agent 协同,支持 MCP server)
- [ProxyCat](https://github.com/honmashironeko/ProxyCat) — 代理池中间件(批量扫描防封 IP)
- [planning-with-files](https://github.com/othmanadi/planning-with-files) — 计划任务 skill(循环测试用)
### 本 skill 内参考文档
- `references/pentest-loop.md` — **核心循环框架**(风险门控 + 记录规范 + 上下文压缩)
- `references/recon-pipeline.md` — **授权侦察流水线**(CF 头 / nmap / Evidence)
- `references/client-side-lab-playbook.md` — **DOM XSS / 原型污染 / agent-browser**(靶场客户端面)
- `references/burpsuite-mcp-guide.md` — **BurpSuite MCP 完整指南**(63 工具 + 7 大使用场景 + AI Prompt 模板)
- `references/automation-loop-pattern.md` — 自动化循环测试模式(轻量版)
- `references/awesome-pentest-digest.md` — 渗透工具精华速查
- `references/pentest-ai-agents-matrix.md` — 35 agent 覆盖矩阵
- `payloads/` — 自定义 payload 目录(AI 优先使用)
- `templates/` — 渗透测试必需文件模板(scope/rules/plan/findings/progress)
---
Files in this skill
- SKILL.md
- references/ai-pentest-agents.md
- references/ai-pentesting-landscape-2026.md
- references/automation-loop-pattern.md
- references/awesome-pentest-digest.md
- references/burpsuite-mcp-guide.md
- references/kali-mcp-ecosystem.md
- references/nuclei-guide-2026.md
- references/pentest-ai-agents-matrix.md
- references/pentest-loop.md
- references/recon-pipeline.md
- templates/findings.md
- templates/progress.md
- templates/rules.md
- templates/scope.md
- templates/task_plan.md
Attribution
Comments
Loading comments…