Skip to content
Back to skills

Tools Nuclei

ASecurity

Operate nuclei for template-based vulnerability scanning at scale — severity/tag selection, bulk targets, rate limiting, proxying, JSON output, and safe custom templates. Load when you have live hosts from recon and need known-CVE/misconfig/exposure sweeps, or when scanner hits need validation. Signals: nuclei, -severity critical,high, nuclei-templates, -tags cve, "9000+ templates", httpx | nuclei pipelines.

  • 20 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
ai-agentspythongobashgit

Works with

  • cli

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add NoorQureshi/SploitAgent --skill tools-nuclei --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Tools Nuclei?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Tools Nuclei
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-tools-nuclei/badge)](https://www.skillsdirectory.com/skills/noorqureshi-tools-nuclei)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: tools-nuclei
description: >
  Operate nuclei for template-based vulnerability scanning at scale — severity/tag selection, bulk
  targets, rate limiting, proxying, JSON output, and safe custom templates. Load when you have live
  hosts from recon and need known-CVE/misconfig/exposure sweeps, or when scanner hits need
  validation. Signals: nuclei, -severity critical,high, nuclei-templates, -tags cve, "9000+
  templates", httpx | nuclei pipelines.
domain: tools
type: technique
stability: learning
modes: [pentest, bugbounty, defense]
severity: info
mitre: [T1595.002]
tools: [nuclei, httpx, subfinder]
schema_version: 1
---

# nuclei vulnerability scanning

## When it applies
Recon has produced live in-scope hosts (`automation-recon-pipeline`) and you want fast coverage of
*known* issues — CVEs, exposed panels, misconfigurations — before spending manual time. Also the
right tool for re-checking a fixed finding across all hosts. For writing a template that codifies
your own finding, load `automation-nuclei-templates` (that skill is the deep guide; the essentials
are below).

## Why it works
nuclei runs declarative YAML templates (9000+ community templates, HTTP/DNS/TCP/SSL/file protocols)
against many targets in parallel with matchers on the response. You trade stealth for breadth: it's
fast and consistent, and loud.

## Method
1. **Install/update:** `apt install nuclei` (Kali) or
   `go install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest`; always
   `nuclei -update-templates` first.
2. **Scope the run — never full-template blindly:**
   ```bash
   nuclei -u https://target.com -severity critical,high        # single host, high signal
   nuclei -u https://target.com -tags cve,exposure             # by tag
   nuclei -l urls.txt -severity critical,high -o results.txt   # bulk targets
   nuclei -u https://target.com -t http/cves/2024/             # one template dir after fingerprinting
   ```
3. **Pipe from recon** (the standard pipeline):
   `subfinder -d target.com -silent | httpx -silent | nuclei -severity critical,high -o report.txt`
4. **Be a good citizen** (and stay under WAF/IDS thresholds):
   `-rate-limit 10 -bulk-size 5` to slow down; `-proxy http://127.0.0.1:8080` to route through Burp
   for visibility; `-exclude-tags dos,fuzz` to skip destructive/noisy checks; `-new-templates` for
   only-recently-added templates on a re-visit.
5. **Capture machine-readable output** for triage: `-json -o results.json`.
6. **Custom template essentials** (full guide: `automation-nuclei-templates`): `id` in
   `vendor-product-vulnerability` form; `info` with honest severity/tags; `http:` block with
   `{{BaseURL}}` paths; combine matchers with `condition: and` and match a signal *unique* to the
   vuln (a computed reflection like `49` from `{{7*7}}`, a specific error string) — never a bare
   200; add an `extractor` that pulls the proof. Validate with `-validate`, then against a
   known-vulnerable and a known-good host.

## Gotchas
- **A nuclei hit is a candidate, not a finding** — templates false-positive on version banners and
  lookalike strings. Manually reproduce every hit (`reporting-triage-validation`) before it goes in
  notes/findings; this is the #1 way automated scanning burns reporter credibility.
- **Full-template runs are loud and slow** — fingerprint first (`recon-techstack-fingerprinting`),
  then run only relevant tags/dirs.
- **Rate limiting cuts both ways** — too fast gets you WAF-banned (and can breach bug-bounty RoE on
  request rates); too slow on a big scope never finishes. Tune `-rate-limit`/`-bulk-size` to the RoE.
- **Windows naming collision** — the `httpx` command on Windows may resolve to the Python httpx
  library's CLI, not ProjectDiscovery's httpx; verify with `httpx -version` before piping.
- **Keep templates read-only** — anything that writes state or can DoS doesn't belong in a mass scan.

## Verify success
Each nuclei hit either reproduces manually with a concrete impact (and gets a findings entry) or is
recorded as a false positive with the reason. The scan config (severity/tags/rate) is logged so the
run is reproducible.

## References
ProjectDiscovery docs; nuclei-templates repo. Writing templates: `automation-nuclei-templates`.
Pipeline context: `automation-recon-pipeline`.

---
_Portions adapted from [reverse-skill](https://github.com/zhaoxuya520/reverse-skill) by zhaoxuya520, MIT License._

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…