H-mmer/pentest-agents

DirSkills catalogs 25 skills from this repository, across 5 categories: AI Engineering, Automation, Data, Quality, Writing.

804 stars156 forksView on GitHub
πŸ•΅οΈ
1w ago

Analyze

Analyze turns recon output into ranked attack paths, crown-jewel targets, and blind spots for a target. Use it before hunting to decide which endpoints and vulnerability classes to test first.
AI Engineering
804156
🧭
1w ago

Autopilot

Autopilot orchestrates autonomous security hunting across a target, loading scope and policy files, dispatching specialist agents, and tracking progress until the exhaustion gates are met. It is used for long-running bug-bounty assessments in interactive or fully autonomous mode.
Automation
804156
🧠
1w ago

Brain

Brain manages pentest engagement state with init, brief, status, exhausted, and record subcommands. Use it to capture targets, evidence, dead ends, and next actions during an assessment.
Automation
804156
🧠
1w ago

Business Logic Hunting

Business Logic Hunting finds logic flaws in payment, auth, and subscription flows such as price manipulation, race conditions, MFA bypass, and trial abuse. Use it when testing for workflow skipping or client-side state trust issues.
Quality
804156
⛓️
1w ago

Chain

Chain builds deep exploit chains from a confirmed bug and dispatches a chain-builder agent to find escalation paths. Use it when you have a validated issue and want end-to-end impact or a reportable chain.
Automation
804156
πŸ”—
1w ago

Correlate

Correlate runs a finding correlation engine to turn individual findings into attack chains. Use it after collecting bugs to identify multi-step paths, document reproduction steps, and surface high-impact chains.
Quality
804156
πŸ’Έ
1w ago

Cost Tracking

Cost Tracking shows engagement spend and return on investment for a pentest run. Use it to review which agents spent the most and whether the work produced findings worth the cost.
Data
804156
πŸ”Ž
1w ago

Duplicate Check

Duplicate Check searches platform hacktivity and local findings to see whether a vulnerability has already been reported. Use it before writing up a finding to judge duplicate risk and related prior art.
Quality
804156
πŸ›‘οΈ
1w ago

Full Scan

Full Scan coordinates a multi-phase security assessment with brain state, skipping exhausted areas and building on prior findings. Use it for broad pentest coverage, targeted testing, and reporting confirmed results.
Automation
804156
πŸ•΅οΈ
1w ago

Hunt

Hunt actively tests a scoped target for vulnerabilities by reading scope and prior findings, detecting the stack, and running targeted probes with concrete payloads. Use it when you need guided recon and exploitation attempts for a specific vuln class.
AI Engineering
804156
πŸ”Ž
1w ago

Hunt IDOR

Hunt IDOR finds insecure direct object references and broken object level authorization issues in web apps, APIs, GraphQL, and multi-tenant services. Use it when testing for cross-tenant data access, object ID tampering, and field-level authorization gaps.
Quality
804156
πŸ•΅οΈ
1w ago

Hunting Methodology

Hunting Methodology guides a non-linear bug bounty workflow from recon and surface mapping through payload testing, validation, chaining, and reporting. Use it to prioritize targets, cover variants, and avoid repeating exhausted paths.
Quality
804156
πŸ•΅οΈ
1w ago

Information Disclosure Hunting

Information Disclosure Hunting finds exposed credentials, leaked secrets, debug endpoints, and other confidentiality-only issues. Use it when checking for .env or .git exposure, Spring Actuator leaks, source disclosure, or stack traces.
Quality
804156
🧠
1w ago

LLM AI Hunting

LLM AI Hunting targets prompt injection, agent tool abuse, output-handling bugs, and model-server RCE in AI features. Use it when testing chatbots, RAG systems, coding agents, MCP servers, or other LLM-integrated surfaces.
AI Engineering
804156
🧠
1w ago

Learn

Learn records a platform response for a report and updates local and global memory. Use it to capture accepted, duplicate, N/A, or severity-change outcomes and turn them into future hunting rules.
Automation
804156
πŸ—ΊοΈ
1w ago

Mindmap

Mindmap generates a text-based attack surface tree that links tech stack, vuln classes, and endpoints. Use it to prioritize testing and record tested, untested, confirmed, and exhausted routes.
Automation
804156
πŸ‘€
1w ago

Monitor

Monitor captures baselines and checks targets for changes in scope, hosts, endpoints, bundles, and policy text. Use it to detect drift and decide which follow-up agents to rerun.
Automation
804156
πŸ”
1w ago

OAuth Hunt

OAuth Hunt finds authorization and identity bugs in OAuth 2.0/2.1, OIDC, SAML SSO, and JWT flows. Use it when testing login, token, redirect, PKCE, claim, or federation logic in web apps, MCP servers, GitOps tools, and identity providers.
Quality
804156
πŸ’₯
1w ago

RCE Hunter

RCE Hunter finds remote code execution attack surfaces in web apps, OSS libraries, CI/CD, containers, and agent tools. Use it when user input may reach shells, deserializers, template engines, loaders, or git and curl commands.
Quality
804156
πŸ•΅οΈ
1w ago

Recon Methodology

Recon Methodology outlines passive and light active steps for bug bounty recon, including subdomain enumeration, URL discovery, tech detection, and content discovery. Use it to organize findings and extract IDOR and SSRF candidates.
Automation
804156
πŸ“
1w ago

Report Writing

Report Writing helps structure pentest and bug bounty findings into clear vulnerability reports with impact, reproduction steps, PoC, CVSS 4.0, and remediation. Use it when you need a submission-ready report that is triager-friendly and evidence-backed.
Writing
804156
πŸ›‘οΈ
1w ago

SAST Methodology

SAST Methodology breaks static analysis into focused agent steps for finding and verifying security bugs. Use it when you need file ranking, flow tracing, gap analysis, PoC confirmation, or adversarial validation.
AI Engineering
804156
πŸ›‘οΈ
1w ago

Triage Validation

Triage Validation applies a gate-based checklist to bug bounty findings. Use it to confirm scope, reproducibility, impact, and whether an issue should be submitted or killed.
Quality
804156
πŸ›‘οΈ
1w ago

Vulnerability Classes

Vulnerability Classes provides testing patterns for common web application flaws such as IDOR, SSRF, XSS, auth bypass, GraphQL, OAuth, race conditions, and file upload issues. Use it when validating security controls or triaging suspected bugs.
Quality
804156
πŸ•·οΈ
1w ago

XSS Hunting

XSS Hunting finds DOM, stored, reflected, postMessage, and mutation-based XSS paths, including sanitizer bypasses and modern framework rendering issues. Use it when testing web apps, markdown renderers, OAuth flows, or message handlers for injection.
Quality
804156