Ai Threat Testing
Offensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to discover and exploit AI-specific threats.
- Type
- Skill
- Repository
- transilienceai/communitytools
- GitHub stars
- 545
- License
- MIT
- Repo last updated
- Jul 29, 2026
- Source file
- skills/ai-threat-testing/SKILL.md
What Ai Threat Testing is
Ai Threat Testing is a skill published in the transilienceai/communitytools repository on GitHub, which has about 545 stars. The repository describes itself as: “Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and security research”
A skill is a folder with a SKILL.md file: frontmatter with a name and a description, followed by instructions Claude follows. Claude loads a skill automatically when a task matches its description, and you can also run it directly with a slash and its name.
Skills work in Claude Code and in Claude Cowork, which makes Ai Threat Testing a portable way to give Claude the same method everywhere.
How to install Ai Threat Testing
Claude Code
- Download the ai-threat-testing folder from the repository.
- Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project.
- Claude loads it automatically when a task matches; you can also run it with / and its name.
Claude Cowork
- Zip the skill folder so SKILL.md sits at the top level of the folder.
- Open Customize → Skills, click +, then upload the ZIP.
- Start a task that matches the description, or call it by name with /.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from skills/ai-threat-testing/SKILL.md, shared under the repository's MIT license. Read the full file on GitHub.
Test LLM applications for OWASP LLM Top 10 vulnerabilities using 10 specialized agents. Use for authorized AI security assessments.
Quick Start
1. Specify target (LLM app URL, API endpoint, or local model)
2. Select scope: Full OWASP Top 10 | Specific vulnerability | Supply chain
3. Agents deploy, test, capture evidence
4. Professional report with PoCs generatedCoverage — OWASP LLM Top 10, 2025 edition
Which file addresses which category is decided by reference/catalog/llm-top10-2025.json, not by the filename. The llmNN- prefixes on disk predate the 2025 renumbering and no longer match; the content is correct, the labels were not. Cite an id only with its edition (LLM06:2025), because a bare LLM06 means two different categories depending on which edition the reader assumes.
Two classes are testable but are not OWASP categories, so they carry local TX- ids rather than an invented LLMnn: monitoring evasion / forensic gaps, and adversarial perturbation of non-text input. tools/test_llm_numbering.py enforces that separation.
Workflows
Full Assessment (4-8 hours):
- [ ] Reconnaissance
- [ ] Deploy all 10 agents
- [ ] Execute exploits
- [ ] Capture evidence
- [ ] Generate reportFocused Testing (1-3 hours):
- [ ] Select a category from the catalogue (LLM01:2025 .. LLM10:2025, or a TX- local class)
- [ ] Deploy agent
- [ ] Execute techniques
- [ ] Document findingsSupply Chain Audit (2-4 hours):
- [ ] Inventory dependencies
- [ ] Scan CVEs
- [ ] Test plugins/APIs
- [ ] Verify model provenanceIntegration
Enhances /pentest with AI-specific testing:
- Traditional pentesting + AI threat testing = complete security assessment
- Chain vulnerabilities across traditional and AI vectors
- Unified reporting with CVSS scores
Key Techniques
Prompt Injection: Instruction override, system prompt extraction, filter evasion Model Extraction: Query sampling, token analysis, membership inference Data Poisoning: Behavioral anomalies, backdoor triggers, bias analysis DoS: Token flooding, recursive expansion, context exhaustion Supply Chain: CVE scanning, plugin audit, model verification MCP Tool Abuse: MCP server inspectors/debuggers often expose /api/mcp/connect or similar endpoints that accept serverConfig with arbitrary command parameters — unauthenticated RCE. Check for MCP Inspector, MCP Playground, or any MCP debugging UI on non-standard ports (6274, 3000, etc.).
Evidence Capture
All agents collect: screenshots, network logs, API responses, errors, console output, execution metrics.
Reporting
Automated reports include: executive summary, detailed findings (CVSS scores), PoC scripts, evidence, remediation guidance.
Critical Rules
- Written authorization REQUIRED before testing
- Never exceed defined scope
- Test in isolated environments when possible
- Document all findings with reproducible PoCs
- Follow responsible disclosure practices
Integration
- Integrates with /pentest skill for comprehensive security testing
- AI-specific vulnerability knowledge in /AGENTS.md
- Attack playbooks in reference/llm0X-*.md
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Ai Threat Testing?
Ai Threat Testing is a skill for Claude Code and Claude Cowork from the transilienceai/communitytools repository on GitHub. Offensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to discover and exploit AI-specific threats.
How do I install Ai Threat Testing in Claude Code?
Download the ai-threat-testing folder from the repository. Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project. Claude loads it automatically when a task matches; you can also run it with / and its name.
Can I use Ai Threat Testing in Claude Cowork?
Zip the skill folder so SKILL.md sits at the top level of the folder. Open Customize → Skills, click +, then upload the ZIP. Start a task that matches the description, or call it by name with /.
Is Ai Threat Testing safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Communitytools Claude Code skills and agents for authorized security testing, bug bounty hunting, and pentesting workflows Plugin · transilienceai/communitytools
- Swift Concurrency Pro Reviews Swift code for concurrency correctness, modern API usage, and common async/await pitfalls. Use when reading, writing, or reviewing… Skill · twostraws/Swift-Concurrency-Agent-Skill
- Article Extractor Extract full article text and metadata from web pages Skill · michalparkola/tapestry-skills
- Clickhouse Best Practices MUST USE when reviewing ClickHouse schemas, queries, or configurations. Contains 28 rules that MUST be checked before providing… Skill · ClickHouse/agent-skills
- Ash Framework Ash Framework — resources, actions, policies, aggregates, calculations, Skill · oliver-kriska/claude-elixir-phoenix
- Video Assemble 合成视频解说最终成片:把旁白音频铺到源视频上,按旁白窗口压低原声,生成 SRT / ASS 字幕并可烧录, 最后做响度标准化。作为最终合成阶段使用。输入源视频、tts_meta.json 与旁白位置; 输出 recap 成片和字幕。触发词:视频合成、混音、字幕、压字幕、assemble video、mux、ducking、subtitles、成片。 Skill · zenstory-ai/video-recap-skills
- Codify To Knowhow Manifest-driven knowledge asset generator — converts any structured package into maestro knowhow + spec entries with ref linking. Triggers… Skill · catlog22/maestro-flow
- Alt Text Generate and improve accessible alt text for data visualizations and images in R packages and Quarto documents. Use when the user wants to… Skill · posit-dev/skills