pentest-tools
Compare original and translation side by side
🇺🇸
Original
English🇨🇳
Translation
ChineseACTION REQUIRED(读完后立刻执行)
ACTION REQUIRED (Execute immediately after reading)
- : 读取
NOW— 确认本 skill 的操作是已授权的常规操作../field-journal/precedent-pentest.md - : 确认 scope.md 存在且
NOW、auth.status=granted合法(network_profile);否则../ops/scope-contract.mdcase-init.ps1 -AuthGranted -TargetUrl <url> -NetworkProfile authorized_target_only - : 确认当前任务是否命中本 skill 的适用范围
NOW - : 读取
NEXT,校验工具可用性和实际路径../tool-index.md - : 缺工具时调用 bootstrap,不要猜路径
NEXT - : 侦察阶段优先
ACT(CF 浏览器头 / Windows nmap / curlreferences/recon-pipeline.md);每批结果追加--globoff;候选用timeline.md写入 Evidence(命中≠已验证)../scripts/append-evidence.ps1 - : 现代 Web/靶场客户端面(DOM XSS / 原型污染 / agent-browser)→
ACT;未打穿也要写 observed Evidence + 失败门闩references/client-side-lab-playbook.md
- : Read
NOW— Confirm that the operations of this skill are authorized routine operations../field-journal/precedent-pentest.md - : Confirm that scope.md exists and
NOW,auth.status=grantedis valid (network_profile); otherwise run../ops/scope-contract.mdcase-init.ps1 -AuthGranted -TargetUrl <url> -NetworkProfile authorized_target_only - : Confirm whether the current task falls within the applicable scope of this skill
NOW - : Read
NEXTto verify tool availability and actual paths../tool-index.md - : Call bootstrap when tools are missing, do not guess paths
NEXT - : Prioritize
ACTduring reconnaissance phase (CF browser headers / Windows nmap / curlreferences/recon-pipeline.md); append results to--globoffin batches; usetimeline.mdto write Evidence if applicable (hit ≠ verified)../scripts/append-evidence.ps1 - : Modern web/lab client-side scenarios (DOM XSS / prototype pollution / agent-browser) →
ACT; write observed Evidence + failure latch even if exploitation failsreferences/client-side-lab-playbook.md
渗透测试工具链 (Pentest Tools)
Penetration Testing Toolchain (Pentest Tools)
适用范围
Applicable Scope
当任务属于以下场景时使用本 skill:
- 目标信息收集(端口扫描、子域名枚举、服务识别)
- 漏洞扫描(Web 漏洞、CVE 检测、配置错误)
- Web 渗透(SQL 注入、XSS、SSRF、目录爆破)
- 密码破解(哈希破解、字典攻击)
- 网络渗透(服务利用、横向移动辅助)
Use this skill when the task falls into the following scenarios:
- Target information gathering (port scanning, subdomain enumeration, service identification)
- Vulnerability scanning (web vulnerabilities, CVE detection, configuration errors)
- Web penetration (SQL injection, XSS, SSRF, directory brute-forcing)
- Password cracking (hash cracking, dictionary attacks)
- Network penetration (service exploitation, lateral movement assistance)
与其他 skill 的分工
Division of Labor with Other Skills
| 场景 | 用什么 |
|---|---|
| 主动扫描/攻击(Nmap/Nuclei/SQLMap) | 本 skill |
| 逆向分析二进制 | |
| 前端 JS 签名逆向 | |
| 浏览器/桌面自动化操作 | |
| CTF 竞赛(综合) | |
简单判断:
- 需要"扫描目标、发现漏洞、利用漏洞" → 本 skill
- 需要"分析程序内部逻辑" → 逆向类 skill
- 需要"操作浏览器/桌面" → browser-automation
| Scenario | What to Use |
|---|---|
| Active scanning/attack (Nmap/Nuclei/SQLMap) | This skill |
| Binary reverse analysis | |
| Frontend JS signature reverse engineering | |
| Browser/desktop automation operations | |
| CTF competitions (comprehensive) | |
Simple judgment:
- Need to "scan targets, discover vulnerabilities, exploit vulnerabilities" → This skill
- Need to "analyze internal program logic" → Reverse engineering skills
- Need to "operate browser/desktop" → browser-automation
工具矩阵
Tool Matrix
信息收集
Information Gathering
| 工具 | 用途 | 典型命令 |
|---|---|---|
| Nmap | 端口扫描、服务识别、OS 检测 | |
| Masscan | 大规模快速端口扫描 | |
| Subfinder | 子域名枚举 | |
| httpx | HTTP 探测、存活检测 | |
| Tool | Purpose | Typical Command |
|---|---|---|
| Nmap | Port scanning, service identification, OS detection | |
| Masscan | Large-scale fast port scanning | |
| Subfinder | Subdomain enumeration | |
| httpx | HTTP probing, liveliness detection | |
漏洞扫描
Vulnerability Scanning
| 工具 | 用途 | 典型命令 |
|---|---|---|
| Nuclei | 模板化漏洞扫描(CVE/配置/暴露) | |
| ZAP | Web 应用安全扫描 | 通过 API 或 MCP 调用 |
| Nikto | Web 服务器漏洞扫描 | |
| Tool | Purpose | Typical Command |
|---|---|---|
| Nuclei | Template-based vulnerability scanning (CVE/configuration/exposure) | |
| ZAP | Web application security scanning | Call via API or MCP |
| Nikto | Web server vulnerability scanning | |
Web 渗透
Web Penetration
| 工具 | 用途 | 典型命令 |
|---|---|---|
| SQLMap | SQL 注入自动化 | |
| FFUF | 目录/参数爆破 | |
| Gobuster | 目录/子域名爆破 | |
| XSStrike | XSS 检测 | |
| Tool | Purpose | Typical Command |
|---|---|---|
| SQLMap | SQL injection automation | |
| FFUF | Directory/parameter brute-forcing | |
| Gobuster | Directory/subdomain brute-forcing | |
| XSStrike | XSS detection | |
密码破解
Password Cracking
| 工具 | 用途 | 典型命令 |
|---|---|---|
| Hashcat | GPU 哈希破解 | |
| John the Ripper | CPU 哈希破解 | |
| Hydra | 在线暴力破解 | |
| Tool | Purpose | Typical Command |
|---|---|---|
| Hashcat | GPU-based hash cracking | |
| John the Ripper | CPU-based hash cracking | |
| Hydra | Online brute-force cracking | |
利用框架
Exploitation Frameworks
| 工具 | 用途 | 说明 |
|---|---|---|
| Metasploit | 漏洞利用框架 | 需要单独安装,体量大 |
| Impacket | Windows 协议利用(SMB/WMI/Kerberos) | |
| Tool | Purpose | Description |
|---|---|---|
| Metasploit | Vulnerability exploitation framework | Requires separate installation, large size |
| Impacket | Windows protocol exploitation (SMB/WMI/Kerberos) | |
MCP 后端选择
MCP Backend Options
本 skill 支持两种 MCP 后端,选一个即可:
This skill supports two MCP backends, choose one:
方案 A:pentestMCP(推荐,Docker 一键)
Option A: pentestMCP (Recommended, one-click Docker)
- 项目:https://github.com/ramkansal/pentestmcp
- 特点:20+ 工具打包成单个 Docker 容器,MCP server 直接暴露
- 工具:Nmap、Nuclei、ZAP、SQLMap、FFUF、Nikto、Gobuster、Subfinder、httpx 等
- 安装:
bash
undefined- Project: https://github.com/ramkansal/pentestmcp
- Features: Packages over 20 tools into a single Docker container, directly exposed via MCP server
- Tools: Nmap, Nuclei, ZAP, SQLMap, FFUF, Nikto, Gobuster, Subfinder, httpx, etc.
- Installation:
bash
undefined拉取并运行
Pull and run
docker pull ramkansal/pentestmcp
docker run -d -p 8080:8080 ramkansal/pentestmcp
docker pull ramkansal/pentestmcp
docker run -d -p 8080:8080 ramkansal/pentestmcp
或本地构建
Or build locally
git clone https://github.com/ramkansal/pentestmcp.git
cd pentestmcp
docker build -t pentestmcp .
docker run -d -p 8080:8080 pentestmcp
- **MCP 注册**:
```json
{
"mcpServers": {
"pentest": {
"url": "http://localhost:8080/mcp"
}
}
}git clone https://github.com/ramkansal/pentestmcp.git
cd pentestmcp
docker build -t pentestmcp .
docker run -d -p 8080:8080 pentestmcp
- **MCP Registration**:
```json
{
"mcpServers": {
"pentest": {
"url": "http://localhost:8080/mcp"
}
}
}方案 B:mcp-security-hub(模块化)
Option B: mcp-security-hub (Modular)
- 项目:https://github.com/FuzzingLabs/mcp-security-hub
- 特点:每个工具独立 MCP server,按需启用
- 工具:Nmap、Ghidra、Nuclei、SQLMap、Hashcat
- 安装:按各子模块 README 操作
- Project: https://github.com/FuzzingLabs/mcp-security-hub
- Features: Each tool has an independent MCP server, enable on demand
- Tools: Nmap, Ghidra, Nuclei, SQLMap, Hashcat
- Installation: Follow the README of each submodule
方案 C:单工具 MCP(最轻量)
Option C: Single-Tool MCP (Lightest)
如果只需要某一个工具:
| 工具 | MCP 项目 | 安装 |
|---|---|---|
| Nmap | nmap-mcp-server | npm |
| Nuclei | nuclei-mcp | npm |
| SQLMap | mcp-security-hub 子模块 | pip |
If only one tool is needed:
| Tool | MCP Project | Installation |
|---|---|---|
| Nmap | nmap-mcp-server | npm |
| Nuclei | nuclei-mcp | npm |
| SQLMap | mcp-security-hub submodule | pip |
Reqable MCP(本地抓包与 API 工作台)
Reqable MCP (Local Packet Capture & API Workbench)
Reqable 桌面客户端可通过官方 Reqable MCP Server 暴露本地抓包、API、断点和规则能力。先单独安装并启动 Reqable,再登记 MCP:
powershell
powershell -NoProfile -ExecutionPolicy Bypass -File skills\scripts\bootstrap-reverse.ps1 -Capability reqable-mcp登记后的 stdio 配置为:
json
{
"mcpServers": {
"reqable-mcp": {
"command": "npx",
"args": ["-y", "reqable-mcp-server@1.0.1", "--scope", "minimal"]
}
}
}- 默认使用 Reqable 的本地 API;必要时按官方文档配置 、
--host或--port。--scope minimal|all - 是推荐默认范围;
minimal会暴露更多会改变代理、规则、环境或已保存数据的工具。all - 对捕获流量、请求重放和规则修改仍须先满足 的授权与网络限制;不得因 MCP 已注册而扩大目标范围。
scope.md
The Reqable desktop client can expose local packet capture, API, breakpoint, and rule capabilities via the official Reqable MCP Server. Install and start Reqable separately first, then register MCP:
powershell
powershell -NoProfile -ExecutionPolicy Bypass -File skills\scripts\bootstrap-reverse.ps1 -Capability reqable-mcpThe registered stdio configuration is:
json
{
"mcpServers": {
"reqable-mcp": {
"command": "npx",
"args": ["-y", "reqable-mcp-server@1.0.1", "--scope", "minimal"]
}
}
}- Uses Reqable's local API by default; configure ,
--host, or--portaccording to official documentation if necessary.--scope minimal|all - is the recommended default scope;
minimalwill expose more tools that can modify proxies, rules, environments, or saved data.all - Capturing traffic, request replay, and rule modification must still comply with the authorization and network restrictions in ; do not expand the target scope just because MCP is registered.
scope.md
工作流
Workflow
标准渗透流程
Standard Penetration Testing Process
重要:执行渗透测试时,必须按的自主循环框架运行。 该框架定义了完整的风险门控、记录规范、上下文压缩和完成检查机制。references/pentest-loop.md
text
1. 信息收集
- Nmap 端口扫描 → 确认开放服务
- Subfinder 子域名枚举 → 扩大攻击面
- httpx 存活检测 → 过滤有效目标
2. 漏洞扫描
- Nuclei 模板扫描 → 快速发现已知漏洞
- ZAP/Nikto → Web 应用深度扫描
3. 漏洞利用
- SQLMap → SQL 注入
- FFUF → 发现隐藏路径/参数
- 手动验证 → 确认可利用性
4. 后渗透(如果授权范围内)
- 权限提升
- 横向移动
- 数据提取
5. 报告
- 调用 docs-generator skill 生成渗透测试报告Important: When performing penetration testing, must run according to the autonomous loop framework in. This framework defines complete risk gating, recording specifications, context compression, and completion checking mechanisms.references/pentest-loop.md
text
1. Information Gathering
- Nmap port scanning → Confirm open services
- Subfinder subdomain enumeration → Expand attack surface
- httpx liveliness detection → Filter valid targets
2. Vulnerability Scanning
- Nuclei template scanning → Quickly discover known vulnerabilities
- ZAP/Nikto → Deep web application scanning
3. Vulnerability Exploitation
- SQLMap → SQL injection
- FFUF → Discover hidden paths/parameters
- Manual verification → Confirm exploitability
4. Post-Exploitation (if within authorized scope)
- Privilege escalation
- Lateral movement
- Data extraction
5. Reporting
- Call docs-generator skill to generate penetration testing report快速扫描流程(5 分钟出结果)
Quick Scanning Process (Results in 5 Minutes)
text
1. nmap -sV -sC target → 端口+服务
2. nuclei -u target -severity critical,high → 高危漏洞
3. 有 Web 服务 → ffuf -u target/FUZZ -w common.txt → 目录
4. 汇总发现 → 决定下一步text
1. nmap -sV -sC target → Ports + services
2. nuclei -u target -severity critical,high → High-risk vulnerabilities
3. If web service exists → ffuf -u target/FUZZ -w common.txt → Directories
4. Summarize findings → Decide next steps注意事项
Notes
- 必须有授权 — 所有扫描/攻击操作必须在授权范围内
- 控制扫描速率 — 避免触发 WAF/IDS 或打崩目标
- 先被动后主动 — 先信息收集,再漏洞扫描,最后利用
- 记录所有操作 — 每个命令和结果都要记录,用于报告
- 不要盲目自动化 — AI 应该在每个关键步骤等待确认
- Authorization Required — All scanning/attack operations must be within authorized scope
- Control Scanning Rate — Avoid triggering WAF/IDS or crashing the target
- Passive Before Active — Gather information first, then scan for vulnerabilities, finally exploit
- Record All Operations — Record every command and result for reporting purposes
- Do Not Blindly Automate — AI should wait for confirmation at each critical step
按需自举(On-Demand Bootstrap)
On-Demand Bootstrap
自动化能力边界
Automation Capability Boundaries
| 工具 | 可自动安装 | 安装方式 | 说明 |
|---|---|---|---|
| Nmap | ✓ | winget ( | Windows 版 |
| Nuclei | ✓ | | 需要 Go 或直接下载二进制 |
| SQLMap | ✓ | | Python |
| FFUF | ✓ | GitHub Release | Go 二进制 |
| SecLists | ✓ | GitHub Release ZIP | 字典大全(FFUF/Gobuster 必备) |
| Hashcat | ✗ | 手动下载 | 需要 GPU 驱动 |
| Metasploit | ✗ | 手动安装 | 体量大,建议用 Kali |
| pentestMCP (Docker) | ✗ | 需要 Docker | |
| Impacket | ✓ | | Python |
| ProxyCat | ✓ | | 代理池中间件(批量扫描防封) |
| BurpSuite MCP | ✗ | BurpSuite 扩展市场安装 | 需要 BurpSuite Pro/Community |
| Reqable MCP | ✓ | | 需先手动安装 Reqable 桌面客户端 |
| Tool | Auto-Installable | Installation Method | Description |
|---|---|---|---|
| Nmap | ✓ | winget ( | Windows version |
| Nuclei | ✓ | | Requires Go or direct binary download |
| SQLMap | ✓ | | Python |
| FFUF | ✓ | GitHub Release | Go binary |
| SecLists | ✓ | GitHub Release ZIP | Wordlist collection (essential for FFUF/Gobuster) |
| Hashcat | ✗ | Manual download | Requires GPU drivers |
| Metasploit | ✗ | Manual installation | Large size, recommended to use Kali |
| pentestMCP (Docker) | ✗ | Requires Docker | |
| Impacket | ✓ | | Python |
| ProxyCat | ✓ | | Proxy pool middleware (prevent IP blocking during batch scanning) |
| BurpSuite MCP | ✗ | Install via BurpSuite Extension Marketplace | Requires BurpSuite Pro/Community |
| Reqable MCP | ✓ | | Require manual installation of Reqable desktop client first |
自举策略
Bootstrap Strategy
- 如果用户有 Docker → 推荐 pentestMCP(一键全家桶)
- 如果没有 Docker → 按需单独安装各工具
- 优先安装 Nmap + Nuclei + SQLMap(覆盖 80% 场景)
- If user has Docker → Recommend pentestMCP (one-click full suite)
- If no Docker → Install tools individually on demand
- Prioritize installing Nmap + Nuclei + SQLMap (covers 80% of scenarios)
手动安装引导
Manual Installation Guide
markdown
⚠️ **渗透工具未安装**
**推荐方案(需要 Docker)**:
docker pull ramkansal/pentestmcp
docker run -d -p 8080:8080 ramkansal/pentestmcp
**轻量方案(逐个安装)**:
- Nmap: winget install Insecure.Nmap
- Nuclei: go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
- SQLMap: pip install sqlmap
- FFUF: 从 https://github.com/ffuf/ffuf/releases 下载
**安装后告诉我,我继续当前任务。**markdown
⚠️ **Penetration tools not installed**
**Recommended Solution (Requires Docker)**:
docker pull ramkansal/pentestmcp
docker run -d -p 8080:8080 ramkansal/pentestmcp
**Lightweight Solution (Install one by one)**:
- Nmap: winget install Insecure.Nmap
- Nuclei: go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
- SQLMap: pip install sqlmap
- FFUF: Download from https://github.com/ffuf/ffuf/releases
**Tell me after installation, and I will continue the current task.**参考资源
Reference Resources
- awesome-pentest — 25k+ stars 渗透工具大全
- SecLists — 字典/payload 集合(FFUF/Gobuster 必备)
- PayloadsAllTheThings — 各类漏洞 payload
- HackTricks — 渗透技巧百科
- pentest-ai-agents — 35 个 Claude Code 渗透子 agent(参考其 prompt 模式)
- Pentest Swarm AI — 群体智能自主渗透框架(多 agent 协同,支持 MCP server)
- ProxyCat — 代理池中间件(批量扫描防封 IP)
- planning-with-files — 计划任务 skill(循环测试用)
- awesome-pentest — Penetration testing tool collection with 25k+ stars
- SecLists — Wordlist/payload collection (essential for FFUF/Gobuster)
- PayloadsAllTheThings — Various vulnerability payloads
- HackTricks — Encyclopedia of penetration techniques
- pentest-ai-agents — 35 Claude Code penetration sub-agents (refer to their prompt mode)
- Pentest Swarm AI — Swarm intelligence autonomous penetration framework (multi-agent collaboration, supports MCP server)
- ProxyCat — Proxy pool middleware (prevent IP blocking during batch scanning)
- planning-with-files — Task planning skill (for loop testing)
本 skill 内参考文档
Internal Reference Documents of This Skill
- — 核心循环框架(风险门控 + 记录规范 + 上下文压缩)
references/pentest-loop.md - — 授权侦察流水线(CF 头 / nmap / Evidence)
references/recon-pipeline.md - — DOM XSS / 原型污染 / agent-browser(靶场客户端面)
references/client-side-lab-playbook.md - — BurpSuite MCP 完整指南(63 工具 + 7 大使用场景 + AI Prompt 模板)
references/burpsuite-mcp-guide.md - — 自动化循环测试模式(轻量版)
references/automation-loop-pattern.md - — 渗透工具精华速查
references/awesome-pentest-digest.md - — 35 agent 覆盖矩阵
references/pentest-ai-agents-matrix.md - — 自定义 payload 目录(AI 优先使用)
payloads/ - — 渗透测试必需文件模板(scope/rules/plan/findings/progress)
templates/
- — Core Loop Framework (risk gating + recording specifications + context compression)
references/pentest-loop.md - — Authorized Reconnaissance Pipeline (CF headers / nmap / Evidence)
references/recon-pipeline.md - — DOM XSS / prototype pollution / agent-browser (lab client-side scenarios)
references/client-side-lab-playbook.md - — Complete BurpSuite MCP Guide (63 tools + 7 usage scenarios + AI prompt templates)
references/burpsuite-mcp-guide.md - — Automated loop testing pattern (lightweight version)
references/automation-loop-pattern.md - — Quick reference for essential penetration tools
references/awesome-pentest-digest.md - — 35-agent coverage matrix
references/pentest-ai-agents-matrix.md - — Custom payload directory (AI priority use)
payloads/ - — Essential penetration testing file templates (scope/rules/plan/findings/progress)
templates/
src-hunter 漏洞挖掘知识库
src-hunter Vulnerability Mining Knowledge Base
src-hunter/- 19 类攻击 playbook(IDOR、RCE、XSS、SQLi、SSRF、OAuth、文件上传等)
- 305 个结构化 payload + 263 个 WAF/EDR 绕过步骤
- 2887 份 HackerOne 已披露 High/Critical 报告
- 88,636 条 WooYun 历史案例统计
- 国产组件指纹和默认凭据
- CVSS 4.0 报告模板
使用方式:AI 在 hunt 阶段自动读取对应 playbook,按其流程测试。
详见 和 。
src-hunter/SKILL.mdsrc-hunter/references/The directory contains complete SRC/Bug Bounty vulnerability mining methodologies:
src-hunter/- 19 attack playbooks (IDOR, RCE, XSS, SQLi, SSRF, OAuth, file upload, etc.)
- 305 structured payloads + 263 WAF/EDR bypass steps
- 2887 disclosed High/Critical reports from HackerOne
- 88,636 statistical cases from WooYun history
- Domestic component fingerprints and default credentials
- CVSS 4.0 report template
Usage: AI automatically reads the corresponding playbook during the hunt phase and tests according to its process.
See and for details.
src-hunter/SKILL.mdsrc-hunter/references/路由上下文
Routing Context
上游入口: (总控)、
触发条件: 需要主动扫描/攻击目标(端口扫描、漏洞检测、注入测试等)
下游出口:
skills/SKILL.mdrouting.md- 发现 Web 漏洞需要进一步分析 →
js-reverse/ - 发现二进制漏洞需要逆向 → 或
ida-reverse/radare2/ - 需要操作浏览器验证漏洞 →
browser-automation/ - 完成后生成报告 →
docs-generator/
同级关联模块: (CTF 中的 Web/Pwn 题会用到这些工具)
CTF-Sandbox-Orchestrator/Upstream Entry: (master control),
Trigger Conditions: Need to actively scan/attack targets (port scanning, vulnerability detection, injection testing, etc.)
Downstream Exports:
skills/SKILL.mdrouting.md- Further analysis needed for discovered web vulnerabilities →
js-reverse/ - Reverse engineering needed for discovered binary vulnerabilities → or
ida-reverse/radare2/ - Browser operation needed to verify vulnerabilities →
browser-automation/ - Generate report after completion →
docs-generator/
Sibling Modules: (these tools are used for Web/Pwn challenges in CTF)
CTF-Sandbox-Orchestrator/任务完成自检(声称完成前 MUST 通过)
Task Completion Self-Check (MUST pass before claiming completion)
- 我是否执行了工作流中的每一步(而不是只阅读)?
- 我是否基于 使用了真实工具路径?
tool-index - 我是否产出了可复现证据(命令/脚本/截图/报告)?
- 我是否完成并回写了 RULES 要求的 Checklist 项?
- Have I executed every step in the workflow (not just read)?
- Have I used real tool paths based on ?
tool-index - Have I produced reproducible evidence (commands/scripts/screenshots/reports)?
- Have I completed and written back the Checklist items required by RULES?