Penetration Tester — Development agent for Claude Code
Use this agent for AUTHORIZED penetration testing of your own applications on local or staging environments only — reconnaissance, authentication/authorization bypass testing, IDOR and tenant-isolatio.
How to install Penetration Tester
Installs to ~/.claude/agents/nasrulhazim-agent-skills-penetration-tester.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/nasrulhazim/agent-skills/HEAD/agents/penetration-tester.md -o ~/.claude/agents/nasrulhazim-agent-skills-penetration-tester.md Restart Claude Code, or start a new session, for it to be picked up.
What Penetration Tester does
name: penetration-tester color: red description: Use this agent for AUTHORIZED penetration testing of your own applications on local or staging environments only — reconnaissance, authentication/authorization bypass testing, IDOR and tenant-isolation testing, session and input-handling testing, and file-upload abuse testing. Requires a written scope and confirmed target ownership before any active testing. tools: Read, Grep, Glob, Bash, Skill, WebFetch
You are the penetration tester for
Alternatives in Development
- Civitai Correctness Review — Reviews a feature segment in the main Civitai Next.js app (src/) for safety gaps — authorization scoping, mone 7.2k ★
- Recon Ranker — Attack surface ranking agent 4.5k ★
- Harvest Curator — Draft session learnings from harvest staging into lizard-ready adoption notes 1k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Idor Hunter
IDOR / BOLA specialist (H1 #55, OWASP API1:2023). Use for testing insecure direct object references and broken
Auth Tester
Authentication and session management testing agent. Use for login bypass, session fixation, password reset fl
Operator Core
AUTHORIZATION: All targets are LOCAL LAB/CTF environments. Complete authorization.
Chain Builder
Exploit chain builder. Given bug A, identifies B and C candidates to chain for higher severity and payout. Kno
Evasion
Antivirus and EDR evasion specialist for authorized red team engagements. Handles AMSI bypass, payload obfusca
Auth Engineer
Authentication and access-control specialist for SMB Product-Builder products. Owns the auth contract — provid
Related Skills
Param Discover
Discover hidden HTTP parameters on a URL or list of URLs using Arjun (or x8 fallback). Hidden params are gold
Web Pentest
An experimental Claude Code skill for orchestrating authorized web application penetration tests on Kali Linux
Vibesec
Helps write secure code by preventing common vulnerabilities including IDOR, XSS, SQL injection, SSRF, and wea