Communitytools
Claude Code skills and agents for authorized security testing, bug bounty hunting, and pentesting workflows
- Type
- Plugin
- Repository
- transilienceai/communitytools
- GitHub stars
- 545
- License
- MIT
- Repo last updated
- Jul 29, 2026
- Source file
- .claude-plugin/plugin.json
- Version
- 1.0.0
- Author
- Transilience AI
What Communitytools is
Communitytools is a plugin published in the transilienceai/communitytools repository on GitHub, which has about 545 stars. The repository describes itself as: “Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and security research”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Communitytools adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Communitytools
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add transilienceai/communitytools
- Install the plugin: claude plugin install communitytools@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter transilienceai/communitytools (the owner/repo shorthand works for GitHub).
- Find Communitytools in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from .claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.
Open-source Claude Code skills and agents for AI-powered penetration testing, bug bounty hunting, AI threat testing, and security reconnaissance — from the team at Transilience.ai
Quick Start | Skills | Architecture | Contributing | Website
Announcement
Practice Makes Perfect: Teaching an AI to Hack by Learning from Its Mistakes (March 2026)
We built an autonomous pentesting agent that scores 100% (104/104) on a published CTF benchmark suite — using only structured markdown skill files, no fine-tuning. Starting from a bare 89.4% baseline, we ran a simple loop roughly 15 times: run the benchmarks, find a failure, diagnose the missing technique, write it into a skill file, and run again. The same skills transfer cross-model: Claude Sonnet 4.6 reaches 96.2% and Claude Haiku 4.5 reaches 62.5%. This repository contains the full skill set described in the paper.
Read the paper
Overview
Transilience AI Community Tools is a consolidated Claude Code security testing suite — 26 skills and 3 tool integrations that cover the full penetration testing lifecycle from reconnaissance to reporting. Agent roles (coordinator, executor, validator) are defined in skills/coordination/ with reference material in skills/coordination/reference/, and spawned dynamically via Agent(prompt=...).
Why Choose Transilience Community Tools?
- AI-Powered Automation — Claude coordinates intelligent security testing workflows
- Complete OWASP Coverage — 100% OWASP Top 10 + OWASP LLM Top 10
- Professional Reporting — CVSS 4.0 (primary; v3.1/v3.0/v2.0 fallback), CWE, MITRE ATT&CK, Transilience-branded PDF reports
- Playwright Integration — Browser automation for client-side vulnerability testing
- Payload-Enriched References — 160+ reference files with inline PayloadsAllTheThings techniques
- Open Source — MIT licensed for commercial and personal use
Prerequisites
Local Setup
- Claude Code — Install Claude Code CLI
- Playwright — Required for client-side testing, HackTheBox/HackerOne automation, and browser-based evidence capture. Install via: npm install -g @playwright/mcp && npx playwright install chromium
- Python 3 — Required for tools (env-reader.py, nvd-lookup.py, slack-send.py)
- Kali Linux tools (optional) — nmap, gobuster, ffuf, sqlmap, testssl, etc. Only needed for network/infrastructure testing
Docker Setup (Recommended)
A single script spins up a Kali Linux container with Claude Code, Playwright (headed via Xvfb), and all Kali security tools pre-installed:
bash scripts/kali-claude-setup.sh projects/pentestThis builds a Docker image with Kali Rolling + Node.js + Claude Code + Playwright + Chromium, mounts the project workspace, and launches Claude Code with --dangerously-skip-permissions. Use --rebuild to force a fresh image build.
Quick Start
1. Clone and enter the project
git clone https://github.com/transilienceai/communitytools.git
cd communitytools/projects/pentest2. Open Claude Code and run skills
claude # Launch Claude Code from the projects/pentest directoryThen use slash commands inside the Claude session:
Pentest https://target.com # Full penetration test (skills/coordination/)
/hackthebox # HackTheBox challenge automation
/hackerone # Bug bounty workflow
/techstack-identification # Passive tech stack recon
/reconnaissance target.com # Attack surface mapping
/source-code-scanning ./app # Static code analysisSkills
All canonical skill and tool definitions live at the repo root (skills/, tools/). Each project under projects/ symlinks only the ones it needs — see Repository Structure for details.
Agent roles (coordinator, executor, validator) are defined in skills/coordination/ with reference material in skills/coordination/reference/, spawned dynamically via Agent(prompt=...).
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Communitytools?
Communitytools is a plugin for Claude Code and Claude Cowork from the transilienceai/communitytools repository on GitHub. Claude Code skills and agents for authorized security testing, bug bounty hunting, and pentesting workflows
How do I install Communitytools in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add transilienceai/communitytools Install the plugin: claude plugin install communitytools@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Communitytools in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter transilienceai/communitytools (the owner/repo shorthand works for GitHub). Find Communitytools in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Communitytools safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Ai Threat Testing Offensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to discover and exploit AI-specific threats. Skill · transilienceai/communitytools
- Video Recap Skills Independent stages plus a thin orchestrator for Chinese-narration recaps from supported video files: local Python/ffmpeg; remote Xiaomi MiMo ASR, VLM, and default TTS; optional Fish Audio TTS with a separate API key or a self-hosted HTTP TTS endpoint; final playback review required. Plugin · zenstory-ai/video-recap-skills
- Phx Elixir/Phoenix/LiveView development with specialist agents, Iron Laws, and Tidewave MCP integration Plugin · oliver-kriska/claude-elixir-phoenix
- Bitwize Music AI music generation workflow for Suno - album concepts, lyrics, prompts, mastering, release Plugin · bitwize-music-studio/claude-ai-music-skills
- Catchup Async-team return-from-absence briefing. /catchup fans out to GitHub, git, Linear, and calendar, then emits one prioritized Context Brief instead of a firehose. Plugin · oliver-kriska/claude-elixir-phoenix
- Agentic Toolkit Reusable infrastructure for building agentic systems with multi-model councils, hierarchical sub-agents, and provenance-tracked tool loops. Lifted from production code (Brandling, 2026 BytePlus Seedance Beta hackathon) and hardened with depth caps + required provenance. Plugin · ooiyeefei/ccc
- Firecrawl Scrape, search, crawl, and map the web with a single command. Plugin · firecrawl/cli
- Deckling Generate native PPTX files using Anthropic Platform Skills. No ugly python-pptx - uses Anthropic's server-side rendering engine. Plugin · ooiyeefei/ccc