Sponsor Suno AI Music arrow_forward
Skill

Ai Threat Testing

Offensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to discover and exploit AI-specific threats.

Type
Skill
GitHub stars
545
License
MIT
Repo last updated
Jul 29, 2026

What Ai Threat Testing is

Ai Threat Testing is a skill published in the transilienceai/communitytools repository on GitHub, which has about 545 stars. The repository describes itself as: “Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and security research”

A skill is a folder with a SKILL.md file: frontmatter with a name and a description, followed by instructions Claude follows. Claude loads a skill automatically when a task matches its description, and you can also run it directly with a slash and its name.

Skills work in Claude Code and in Claude Cowork, which makes Ai Threat Testing a portable way to give Claude the same method everywhere.

How to install Ai Threat Testing

Claude Code

  1. Download the ai-threat-testing folder from the repository.
  2. Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project.
  3. Claude loads it automatically when a task matches; you can also run it with / and its name.

Claude Cowork

  1. Zip the skill folder so SKILL.md sits at the top level of the folder.
  2. Open Customize → Skills, click +, then upload the ZIP.
  3. Start a task that matches the description, or call it by name with /.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from skills/ai-threat-testing/SKILL.md, shared under the repository's MIT license. Read the full file on GitHub.

Test LLM applications for OWASP LLM Top 10 vulnerabilities using 10 specialized agents. Use for authorized AI security assessments.

Quick Start

1. Specify target (LLM app URL, API endpoint, or local model)
2. Select scope: Full OWASP Top 10 | Specific vulnerability | Supply chain
3. Agents deploy, test, capture evidence
4. Professional report with PoCs generated

Coverage — OWASP LLM Top 10, 2025 edition

Which file addresses which category is decided by reference/catalog/llm-top10-2025.json, not by the filename. The llmNN- prefixes on disk predate the 2025 renumbering and no longer match; the content is correct, the labels were not. Cite an id only with its edition (LLM06:2025), because a bare LLM06 means two different categories depending on which edition the reader assumes.

Two classes are testable but are not OWASP categories, so they carry local TX- ids rather than an invented LLMnn: monitoring evasion / forensic gaps, and adversarial perturbation of non-text input. tools/test_llm_numbering.py enforces that separation.

Workflows

Full Assessment (4-8 hours):

- [ ] Reconnaissance
- [ ] Deploy all 10 agents
- [ ] Execute exploits
- [ ] Capture evidence
- [ ] Generate report

Focused Testing (1-3 hours):

- [ ] Select a category from the catalogue (LLM01:2025 .. LLM10:2025, or a TX- local class)
- [ ] Deploy agent
- [ ] Execute techniques
- [ ] Document findings

Supply Chain Audit (2-4 hours):

- [ ] Inventory dependencies
- [ ] Scan CVEs
- [ ] Test plugins/APIs
- [ ] Verify model provenance

Integration

Enhances /pentest with AI-specific testing:

  • Traditional pentesting + AI threat testing = complete security assessment
  • Chain vulnerabilities across traditional and AI vectors
  • Unified reporting with CVSS scores

Key Techniques

Prompt Injection: Instruction override, system prompt extraction, filter evasion Model Extraction: Query sampling, token analysis, membership inference Data Poisoning: Behavioral anomalies, backdoor triggers, bias analysis DoS: Token flooding, recursive expansion, context exhaustion Supply Chain: CVE scanning, plugin audit, model verification MCP Tool Abuse: MCP server inspectors/debuggers often expose /api/mcp/connect or similar endpoints that accept serverConfig with arbitrary command parameters — unauthenticated RCE. Check for MCP Inspector, MCP Playground, or any MCP debugging UI on non-standard ports (6274, 3000, etc.).

Evidence Capture

All agents collect: screenshots, network logs, API responses, errors, console output, execution metrics.

Reporting

Automated reports include: executive summary, detailed findings (CVSS scores), PoC scripts, evidence, remediation guidance.

Critical Rules

  • Written authorization REQUIRED before testing
  • Never exceed defined scope
  • Test in isolated environments when possible
  • Document all findings with reproducible PoCs
  • Follow responsible disclosure practices

Integration

  • Integrates with /pentest skill for comprehensive security testing
  • AI-specific vulnerability knowledge in /AGENTS.md
  • Attack playbooks in reference/llm0X-*.md

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Ai Threat Testing?

Ai Threat Testing is a skill for Claude Code and Claude Cowork from the transilienceai/communitytools repository on GitHub. Offensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to discover and exploit AI-specific threats.

How do I install Ai Threat Testing in Claude Code?

Download the ai-threat-testing folder from the repository. Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project. Claude loads it automatically when a task matches; you can also run it with / and its name.

Can I use Ai Threat Testing in Claude Cowork?

Zip the skill folder so SKILL.md sits at the top level of the folder. Open Customize → Skills, click +, then upload the ZIP. Start a task that matches the description, or call it by name with /.

Is Ai Threat Testing safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.