Skip to content
Back to skills

Pentest Tools

ASecurity

主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。

  • 434 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 23, 2026
ai-agentsgosqlgitapisecurity

Works with

  • claude code
  • cli
  • api
  • mcp

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 16 files and shows the line behind each finding

Scanned September 23, 2026

npx -y skills add coco-research/coco --skill pentest-tools --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Pentest Tools?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Pentest Tools
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/coco-research-pentest-tools/badge)](https://www.skillsdirectory.com/skills/coco-research-pentest-tools)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: pentest-tools
description: |
  主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。
  通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。
  触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。
user-invocable: true
---

# 渗透测试工具链 (Pentest Tools)

## 适用范围

当任务属于以下场景时使用本 skill:

- 目标信息收集(端口扫描、子域名枚举、服务识别)
- 漏洞扫描(Web 漏洞、CVE 检测、配置错误)
- Web 渗透(SQL 注入、XSS、SSRF、目录爆破)
- 密码破解(哈希破解、字典攻击)
- 网络渗透(服务利用、横向移动辅助)

### 与其他 skill 的分工

| 场景 | 用什么 |
|------|--------|
| 主动扫描/攻击(Nmap/Nuclei/SQLMap) | **本 skill** |
| 逆向分析二进制 | `ida-reverse/` 或 `radare2/` |
| 前端 JS 签名逆向 | `js-reverse/` |
| 浏览器/桌面自动化操作 | `browser-automation/` |
| CTF 竞赛(综合) | `CTF-Sandbox-Orchestrator/` |

简单判断:
- 需要"扫描目标、发现漏洞、利用漏洞" → 本 skill
- 需要"分析程序内部逻辑" → 逆向类 skill
- 需要"操作浏览器/桌面" → browser-automation

---

## 工具矩阵

### 信息收集

| 工具 | 用途 | 典型命令 |
|------|------|---------|
| **Nmap** | 端口扫描、服务识别、OS 检测 | `nmap -sV -sC -O target` |
| **Masscan** | 大规模快速端口扫描 | `masscan -p1-65535 target --rate=1000` |
| **Subfinder** | 子域名枚举 | `subfinder -d target.com` |
| **httpx** | HTTP 探测、存活检测 | `httpx -l urls.txt -status-code` |

### 漏洞扫描

| 工具 | 用途 | 典型命令 |
|------|------|---------|
| **Nuclei** | 模板化漏洞扫描(CVE/配置/暴露) | `nuclei -u target -t cves/` |
| **ZAP** | Web 应用安全扫描 | 通过 API 或 MCP 调用 |
| **Nikto** | Web 服务器漏洞扫描 | `nikto -h target` |

### Web 渗透

| 工具 | 用途 | 典型命令 |
|------|------|---------|
| **SQLMap** | SQL 注入自动化 | `sqlmap -u "url?id=1" --batch --dbs` |
| **FFUF** | 目录/参数爆破 | `ffuf -u target/FUZZ -w wordlist.txt` |
| **Gobuster** | 目录/子域名爆破 | `gobuster dir -u target -w wordlist` |
| **XSStrike** | XSS 检测 | `xsstrike -u "url?param=test"` |

### 密码破解

| 工具 | 用途 | 典型命令 |
|------|------|---------|
| **Hashcat** | GPU 哈希破解 | `hashcat -m 0 hash.txt wordlist.txt` |
| **John the Ripper** | CPU 哈希破解 | `john --wordlist=rockyou.txt hash.txt` |
| **Hydra** | 在线暴力破解 | `hydra -l admin -P pass.txt target ssh` |

### 利用框架

| 工具 | 用途 | 说明 |
|------|------|------|
| **Metasploit** | 漏洞利用框架 | 需要单独安装,体量大 |
| **Impacket** | Windows 协议利用(SMB/WMI/Kerberos) | `pip install impacket` |

---

## 工作流

### 标准渗透流程

> **重要**:执行渗透测试时,必须按 `references/pentest-loop.md` 的自主循环框架运行。
> 该框架定义了完整的风险门控、记录规范、上下文压缩和完成检查机制。

```text
1. 信息收集
   - Nmap 端口扫描 → 确认开放服务
   - Subfinder 子域名枚举 → 扩大攻击面
   - httpx 存活检测 → 过滤有效目标

2. 漏洞扫描
   - Nuclei 模板扫描 → 快速发现已知漏洞
   - ZAP/Nikto → Web 应用深度扫描

3. 漏洞利用
   - SQLMap → SQL 注入
   - FFUF → 发现隐藏路径/参数
   - 手动验证 → 确认可利用性

4. 后渗透(如果授权范围内)
   - 权限提升
   - 横向移动
   - 数据提取

5. 报告
   - 调用 docs-generator skill 生成渗透测试报告
```

### 快速扫描流程(5 分钟出结果)

```text
1. nmap -sV -sC target → 端口+服务
2. nuclei -u target -severity critical,high → 高危漏洞
3. 有 Web 服务 → ffuf -u target/FUZZ -w common.txt → 目录
4. 汇总发现 → 决定下一步
```

---

## 注意事项

- **必须有授权** — 所有扫描/攻击操作必须在授权范围内
- **控制扫描速率** — 避免触发 WAF/IDS 或打崩目标
- **先被动后主动** — 先信息收集,再漏洞扫描,最后利用
- **记录所有操作** — 每个命令和结果都要记录,用于报告
- **不要盲目自动化** — AI 应该在每个关键步骤等待确认

---

## 参考资源

- [awesome-pentest](https://github.com/enaqx/awesome-pentest) — 25k+ stars 渗透工具大全
- [SecLists](https://github.com/danielmiessler/SecLists) — 字典/payload 集合(FFUF/Gobuster 必备)
- [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings) — 各类漏洞 payload
- [HackTricks](https://book.hacktricks.wiki/) — 渗透技巧百科
- [pentest-ai-agents](https://github.com/0xSteph/pentest-ai-agents) — 35 个 Claude Code 渗透子 agent(参考其 prompt 模式)
- [Pentest Swarm AI](https://github.com/Armur-Ai/Pentest-Swarm-AI) — 群体智能自主渗透框架(多 agent 协同,支持 MCP server)
- [ProxyCat](https://github.com/honmashironeko/ProxyCat) — 代理池中间件(批量扫描防封 IP)
- [planning-with-files](https://github.com/othmanadi/planning-with-files) — 计划任务 skill(循环测试用)

### 本 skill 内参考文档

- `references/pentest-loop.md` — **核心循环框架**(风险门控 + 记录规范 + 上下文压缩)
- `references/recon-pipeline.md` — **授权侦察流水线**(CF 头 / nmap / Evidence)
- `references/client-side-lab-playbook.md` — **DOM XSS / 原型污染 / agent-browser**(靶场客户端面)
- `references/burpsuite-mcp-guide.md` — **BurpSuite MCP 完整指南**(63 工具 + 7 大使用场景 + AI Prompt 模板)
- `references/automation-loop-pattern.md` — 自动化循环测试模式(轻量版)
- `references/awesome-pentest-digest.md` — 渗透工具精华速查
- `references/pentest-ai-agents-matrix.md` — 35 agent 覆盖矩阵
- `payloads/` — 自定义 payload 目录(AI 优先使用)
- `templates/` — 渗透测试必需文件模板(scope/rules/plan/findings/progress)

---

Files in this skill

  • SKILL.md6.2 KB
  • references/ai-pentest-agents.md6 KB
  • references/ai-pentesting-landscape-2026.md3.4 KB
  • references/automation-loop-pattern.md5.2 KB
  • references/awesome-pentest-digest.md5.9 KB
  • references/burpsuite-mcp-guide.md23 KB
  • references/kali-mcp-ecosystem.md4.4 KB
  • references/nuclei-guide-2026.md4 KB
  • references/pentest-ai-agents-matrix.md5 KB
  • references/pentest-loop.md6.6 KB
  • references/recon-pipeline.md5.7 KB
  • templates/findings.md328 B
  • templates/progress.md242 B
  • templates/rules.md722 B
  • templates/scope.md422 B
  • templates/task_plan.md543 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…