BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

claude-pentest

Skill Security Usable
Works inClaude Code
Usable Scanned — metadata only

Reduces manual reconnaissance and vulnerability discovery cycles by automating pentesting workflows within Claude, enabling security teams to scale assessmen…

A Claude Code plugin that gives Claude structured, human-in-the-loop penetration testing capabilities. A single /pentest command coordinates the engagement — running reconnaissance, asking a planner agent for a deployment plan, then dispatching specialized executor agents across 63 attack categories, with operator approval required before any active exploitation. Every finding ships with a working proof-of-concept and captured HTTP/screenshot evidence. For authorized security testing only.

90 starsMIT (commercial OK)FreeQuick setup
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Reduces manual reconnaissance and vulnerability discovery cycles by automating pentesting workflows within Claude, enabling security teams to scale assessment coverage without expanding headcount.

Security teams and penetration testers conducting authorized security assessments and vulnerability research.

Claude Code Claude Cowork Claude Chat

https://github.com/Stickman230/claude-pentest

By Stickman230

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Instructions to paste into Claude
/plugin marketplace add Stickman230/claude-pentest
/plugin install pentest@claude-pentest
First thing to try

After installing, paste this into Claude:

Identify security vulnerabilities in my web application code
CostFree

Trust Signals Auto-scanned

Stars90Contributors1Last updated2026-06-08LicenseMIT (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-08-17 · scanner v1

Community Pulse New

No community discussions found yet. This doesn't mean the tool isn't good — it may be new or serve a niche use case.

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

Scored from trust signals (evidence-eval-v1): 48 GitHub stars; contributors unknown; last commit 0d ago; license MIT.

Things to check

  • Scanned, not hands-on tested — this entry was auto-scanned from public metadata (GitHub metrics, license, security flags). No reviewer has run it, and no tool-specific limitations have been documented yet.
  • Single maintainer. Consider the risk if this person stops maintaining the project.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
2/5
Reliability
3/5
Security
3/5
Overall score2.75 / 5.00 UsableEvaluatedJun 2026
Scored from trust signals (evidence-eval-v1): 48 GitHub stars; contributors unknown; last commit 0d ago; license MIT.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →