Penetration Tester (penetration-tester--plugin)
25-skill pentest pack with engagement governance, network/code/dependency scans, OWASP Top 10 mapping, and exec-readable reporting. Heavy-hitter compliant; chain-of-custody attestable.
- Type
- Plugin
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Version
- 3.30.0
- Author
- Jeremy Longshore
What Penetration Tester (penetration-tester--plugin) is
Penetration Tester (penetration-tester--plugin) is a plugin published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Penetration Tester adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Penetration Tester (penetration-tester--plugin)
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace
- Install the plugin: claude plugin install penetration-tester@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub).
- Find Penetration Tester in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/security/penetration-tester/.claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.
Security testing toolkit for web applications, dependencies, and source code. Three real scanners that wrap established tools (requests, bandit, pip-audit, npm audit) with unified reporting.
What It Does
Installation
/plugin install penetration-tester@claude-code-plugins-plusSetup
Install Python dependencies:
bash scripts/setup_pentest_env.shOr with a virtual environment:
bash scripts/setup_pentest_env.sh --venvRequires Python 3.9+. The setup script installs requests, bandit, and pip-audit, then verifies each tool works.
Quick Start
Check security headers on a URL:
> Check the security headers on https://example.comAudit project dependencies:
> Audit the dependencies in this project for vulnerabilitiesScan code for security issues:
> Scan this codebase for hardcoded secrets and security issuesFull security audit:
> Run a full security audit on this projectScanners
security_scanner.py
HTTP security analysis for live web applications.
python3 scripts/security_scanner.py https://example.com
python3 scripts/security_scanner.py https://example.com --checks headers,ssl
python3 scripts/security_scanner.py https://example.com --output report.jsonChecks:
- Security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy)
- SSL/TLS certificate validity and expiry
- Exposed endpoints (.git, .env, admin panels, server-status)
- Dangerous HTTP methods (PUT, DELETE, TRACE)
- CORS misconfigurations (wildcard, reflected origin)
dependency_auditor.py
Unified dependency vulnerability scanner.
python3 scripts/dependency_auditor.py /path/to/project
python3 scripts/dependency_auditor.py . --min-severity high
python3 scripts/dependency_auditor.py . --scanners npm,pip --output findings.jsonSupports:
- npm projects (via npm audit)
- Python projects (via pip-audit)
- Auto-detects project type from manifest files
code_security_scanner.py
Static analysis for security vulnerabilities.
python3 scripts/code_security_scanner.py /path/to/code
python3 scripts/code_security_scanner.py . --tools bandit,regex --severity high
python3 scripts/code_security_scanner.py . --exclude "test_*,*_test.py"Detects:
- Hardcoded secrets (API keys, AWS keys, passwords, tokens)
- SQL injection (string concatenation in queries)
- Command injection (os.system, subprocess with shell=True)
- Eval/exec usage
- Insecure deserialization (pickle, unsafe YAML loading)
- Weak cryptography (MD5, SHA1)
- Disabled SSL verification
Output
All scanners produce:
- Markdown-formatted reports for terminal display
- JSON reports via --output for programmatic use
- Risk scoring with severity levels (critical, high, medium, low, info)
- Remediation guidance for each finding
Exit code 0 means no critical or high findings. Exit code 1 means issues found.
Reference Documentation
The references/ directory contains detailed guides:
- OWASP_TOP_10.md -- Each OWASP Top 10 risk with scanner mapping and fix templates
- SECURITY_HEADERS.md -- HTTP header implementation for Express, Django, Nginx, Apache
- REMEDIATION_PLAYBOOK.md -- Copy-paste fix templates for common vulnerabilities
Authorization Warning
Only test systems you are authorized to test.
- Never scan URLs you do not own or have written permission to test
- Local code scanning and dependency auditing of your own projects is always safe
- The scanners will ask for authorization confirmation before external scans
- Unauthorized security testing may violate laws in your jurisdiction
Commands
- /pentest -- Full security testing workflow with authorization checks
- /scan-headers -- Quick security header check for a single URL
Requirements
- Python 3.9+
- requests >= 2.31.0
- bandit >= 1.7.5 (optional, for code scanning)
- pip-audit >= 2.6.0 (optional, for Python dependency auditing)
- npm (optional, for JavaScript dependency auditing)
Contributors
- @duskfallcrew -- Reported AV false positive from PHP payloads in docs (#300), prompting the v2.0.0 rebuild
License
MIT License - See LICENSE file for details.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Penetration Tester (penetration-tester--plugin)?
Penetration Tester (penetration-tester--plugin) is a plugin for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. 25-skill pentest pack with engagement governance, network/code/dependency scans, OWASP Top 10 mapping, and exec-readable reporting. Heavy-hitter compliant; chain-of-custody attestable.
How do I install Penetration Tester (penetration-tester--plugin) in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace Install the plugin: claude plugin install penetration-tester@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Penetration Tester (penetration-tester--plugin) in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub). Find Penetration Tester in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Penetration Tester (penetration-tester--plugin) safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Persona Pack Operator-grade Persona identity workflow pack with 18 skills for inquiry lifecycles, authentic webhooks, privacy, reliability, and governed production delivery Plugin · jeremylongshore/tons-of-skills-marketplace
- Pipeline Orchestrate Orchestrate complex multi-stage deployment pipelines Slash Command · jeremylongshore/tons-of-skills-marketplace
- Phish Designs phishing simulation programs, security awareness curricula, and social engineering assessments that drive behavior change through immediate feedback and difficulty progression. Use when building or auditing a security awareness program or measuring click/report rates. Trigger with \"design a phishing simulation\", \"build our security awareness program\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Pipeline Optimize Analyze and optimize slow CI/CD pipelines Slash Command · jeremylongshore/tons-of-skills-marketplace
- Performance Budget Validator Validate application against performance budgets Plugin · jeremylongshore/tons-of-skills-marketplace
- Palantir Pack Evidence-backed Palantir Foundry operator workflows for data pipelines, Ontology applications, DevOps, governance, security, and operations (24 skills) Plugin · jeremylongshore/tons-of-skills-marketplace
- Performance Optimization Advisor Get comprehensive performance optimization recommendations Plugin · jeremylongshore/tons-of-skills-marketplace
- Pair Programmer Graduated assistance framework to prevent skill atrophy when coding with AI Plugin · jeremylongshore/tons-of-skills-marketplace