Sponsor Suno AI Music arrow_forward
Plugin

Communitytools

Claude Code skills and agents for authorized security testing, bug bounty hunting, and pentesting workflows

Type
Plugin
GitHub stars
545
License
MIT
Repo last updated
Jul 29, 2026
Version
1.0.0
Author
Transilience AI

What Communitytools is

Communitytools is a plugin published in the transilienceai/communitytools repository on GitHub, which has about 545 stars. The repository describes itself as: “Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and security research”

A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.

Installing Communitytools adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.

How to install Communitytools

Claude Code

  1. Add the repository as a plugin marketplace: claude plugin marketplace add transilienceai/communitytools
  2. Install the plugin: claude plugin install communitytools@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
  3. Restart the session if the new skills or commands don't appear straight away.

Claude Cowork

  1. Open Customize → Plugins and choose Add marketplace.
  2. Enter transilienceai/communitytools (the owner/repo shorthand works for GitHub).
  3. Find Communitytools in the list, click Install, then connect any connectors it needs from its Connectors tab.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from .claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.

Open-source Claude Code skills and agents for AI-powered penetration testing, bug bounty hunting, AI threat testing, and security reconnaissance — from the team at Transilience.ai

Quick Start | Skills | Architecture | Contributing | Website

Announcement

Practice Makes Perfect: Teaching an AI to Hack by Learning from Its Mistakes (March 2026)

We built an autonomous pentesting agent that scores 100% (104/104) on a published CTF benchmark suite — using only structured markdown skill files, no fine-tuning. Starting from a bare 89.4% baseline, we ran a simple loop roughly 15 times: run the benchmarks, find a failure, diagnose the missing technique, write it into a skill file, and run again. The same skills transfer cross-model: Claude Sonnet 4.6 reaches 96.2% and Claude Haiku 4.5 reaches 62.5%. This repository contains the full skill set described in the paper.

Read the paper

Overview

Transilience AI Community Tools is a consolidated Claude Code security testing suite — 26 skills and 3 tool integrations that cover the full penetration testing lifecycle from reconnaissance to reporting. Agent roles (coordinator, executor, validator) are defined in skills/coordination/ with reference material in skills/coordination/reference/, and spawned dynamically via Agent(prompt=...).

Why Choose Transilience Community Tools?

  • AI-Powered Automation — Claude coordinates intelligent security testing workflows
  • Complete OWASP Coverage — 100% OWASP Top 10 + OWASP LLM Top 10
  • Professional Reporting — CVSS 4.0 (primary; v3.1/v3.0/v2.0 fallback), CWE, MITRE ATT&CK, Transilience-branded PDF reports
  • Playwright Integration — Browser automation for client-side vulnerability testing
  • Payload-Enriched References — 160+ reference files with inline PayloadsAllTheThings techniques
  • Open Source — MIT licensed for commercial and personal use

Prerequisites

Local Setup

  • Claude Code — Install Claude Code CLI
  • Playwright — Required for client-side testing, HackTheBox/HackerOne automation, and browser-based evidence capture. Install via: npm install -g @playwright/mcp && npx playwright install chromium
  • Python 3 — Required for tools (env-reader.py, nvd-lookup.py, slack-send.py)
  • Kali Linux tools (optional) — nmap, gobuster, ffuf, sqlmap, testssl, etc. Only needed for network/infrastructure testing

Docker Setup (Recommended)

A single script spins up a Kali Linux container with Claude Code, Playwright (headed via Xvfb), and all Kali security tools pre-installed:

bash scripts/kali-claude-setup.sh projects/pentest

This builds a Docker image with Kali Rolling + Node.js + Claude Code + Playwright + Chromium, mounts the project workspace, and launches Claude Code with --dangerously-skip-permissions. Use --rebuild to force a fresh image build.

Quick Start

1. Clone and enter the project

git clone https://github.com/transilienceai/communitytools.git
cd communitytools/projects/pentest

2. Open Claude Code and run skills

claude    # Launch Claude Code from the projects/pentest directory

Then use slash commands inside the Claude session:

Pentest https://target.com            # Full penetration test (skills/coordination/)
/hackthebox                          # HackTheBox challenge automation
/hackerone                           # Bug bounty workflow
/techstack-identification            # Passive tech stack recon
/reconnaissance target.com           # Attack surface mapping
/source-code-scanning ./app          # Static code analysis

Skills

All canonical skill and tool definitions live at the repo root (skills/, tools/). Each project under projects/ symlinks only the ones it needs — see Repository Structure for details.

Agent roles (coordinator, executor, validator) are defined in skills/coordination/ with reference material in skills/coordination/reference/, spawned dynamically via Agent(prompt=...).

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Communitytools?

Communitytools is a plugin for Claude Code and Claude Cowork from the transilienceai/communitytools repository on GitHub. Claude Code skills and agents for authorized security testing, bug bounty hunting, and pentesting workflows

How do I install Communitytools in Claude Code?

Add the repository as a plugin marketplace: claude plugin marketplace add transilienceai/communitytools Install the plugin: claude plugin install communitytools@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.

Can I use Communitytools in Claude Cowork?

Open Customize → Plugins and choose Add marketplace. Enter transilienceai/communitytools (the owner/repo shorthand works for GitHub). Find Communitytools in the list, click Install, then connect any connectors it needs from its Connectors tab.

Is Communitytools safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.