Pentest Validator — Security agent for Claude Code
Optional, disabled-by-default Dynamic Security Validation agent.
How to install Pentest Validator
Installs to ~/.claude/agents/felipegiannetti-claude-security-agents-pentest-validator.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/felipegiannetti/claude-security-agents/HEAD/agents/pentest-validator.md -o ~/.claude/agents/felipegiannetti-claude-security-agents-pentest-validator.md Restart Claude Code, or start a new session, for it to be picked up.
What Pentest Validator does
name: pentest-validator description: Optional, disabled-by-default Dynamic Security Validation agent. Interacts with a running, explicitly authorized instance of the application to confirm specific candidate/verified findings (BOLA/IDOR, SSRF, auth/authz, insecure API behavior) that benefit from real-world confirmation. Unlike every other agent in this project, it is not read-only against a running target — but it is never active by default, never assumes authorization, and never performs de
Alternatives in Security
- Anti Reversing Techniques — AUTHORIZED USE ONLY: This skill contains dual-use security techniques 31.9k ★
- Brain — Central knowledge coordinator 812 ★
- Mobile Reverser — Deep Mobile Security Red Team persona 548 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Vuln Verifier
Adjudicates a single candidate security finding produced by the vuln-analyst hunter. Independently re-reads th
API Attacker
API security testing specialist for REST, GraphQL, gRPC, and WebSocket APIs. Handles BOLA/IDOR, mass assignmen
Kavach API
KAVACH API security + auth/session specialist. Traces every endpoint for BOLA/IDOR, BFLA, broken auth, mass as
Exploit Validator
Adversarial validation specialist. Receives candidate findings it did NOT discover and tries to refute each on
SEO Page Auditor
Audits one URL against the measurable on-page checks and writes structured findings to a file. Use when auditi
Log Reviewer
Audit roku-log usage in a JellyRock BS/BRS file or function. Defaults to AUDIT-ONLY: lists logging gaps withou
Related Skills
Web Pentest
An experimental Claude Code skill for orchestrating authorized web application penetration tests on Kali Linux
API Security
API security audit (OWASP API Security Top 10 2023): BOLA/IDOR, broken authentication, broken object-property-
Hunt Access
Active IDOR / BOLA / BFLA / mass-assignment hunt for an ingested program. Consumes the webvuln-surface seeds +