{
  "markdown": "# Transilience AI Community Security Tools\n\n<div align=\"center\">\n\n[![Built by Transilience](https://img.shields.io/badge/Built%20by-Transilience.ai-4A90D9)](https://www.transilience.ai)\n[![MIT License](https://img.shields.io/badge/License-MIT-green.svg)](https://choosealicense.com/licenses/mit/)\n[![GitHub stars](https://img.shields.io/github/stars/transilienceai/communitytools)](https://github.com/transilienceai/communitytools/stargazers)\n[![Claude AI](https://img.shields.io/badge/Powered%20by-Claude%20AI-blue)](https://claude.ai)\n\n**Open-source Claude Code skills and agents for AI-powered penetration testing, bug bounty hunting, AI threat testing, and security reconnaissance — from the team at [Transilience.ai](https://www.transilience.ai)**\n\n[Quick Start](#-quick-start) | [Skills](#-skills) | [Architecture](#-architecture) | [Contributing](CONTRIBUTING.md) | [Website](https://www.transilience.ai)\n\n</div>\n\n---\n\n## Announcement\n\n**Practice Makes Perfect: Teaching an AI to Hack by Learning from Its Mistakes** (March 2026)\n\nWe built an autonomous pentesting agent that scores **100% (104/104)** on a published CTF benchmark suite — using only structured markdown skill files, no fine-tuning. Starting from a bare 89.4% baseline, we ran a simple loop roughly 15 times: run the benchmarks, find a failure, diagnose the missing technique, write it into a skill file, and run again. The same skills transfer cross-model: Claude Sonnet 4.6 reaches 96.2% and Claude Haiku 4.5 reaches 62.5%. This repository contains the full skill set described in the paper.\n\n**[Read the paper](papers/practice-makes-perfect.pdf)**\n\n---\n\n## Overview\n\n**Transilience AI Community Tools** is a consolidated Claude Code security testing suite — **26 skills** and **3 tool integrations** that cover the full penetration testing lifecycle from reconnaissance to reporting. Agent roles (coordinator, executor, validator) are defined in `skills/coordination/` with reference material in `skills/coordination/reference/`, and spawned dynamically via `Agent(prompt=...)`.\n\n### Why Choose Transilience Community Tools?\n\n- **AI-Powered Automation** — Claude coordinates intelligent security testing workflows\n- **Complete OWASP Coverage** — 100% OWASP Top 10 + OWASP LLM Top 10\n- **Professional Reporting** — CVSS 4.0 (primary; v3.1/v3.0/v2.0 fallback), CWE, MITRE ATT&CK, Transilience-branded PDF reports\n- **Playwright Integration** — Browser automation for client-side vulnerability testing\n- **Payload-Enriched References** — 160+ reference files with inline PayloadsAllTheThings techniques\n- **Open Source** — MIT licensed for commercial and personal use\n\n---\n\n## Prerequisites\n\n### Local Setup\n\n- **Claude Code** — [Install Claude Code CLI](https://docs.anthropic.com/en/docs/claude-code/overview)\n- **Playwright** — Required for client-side testing, HackTheBox/HackerOne automation, and browser-based evidence capture. Install via: `npm install -g @playwright/mcp && npx playwright install chromium`\n- **Python 3** — Required for tools (`env-reader.py`, `nvd-lookup.py`, `slack-send.py`)\n- **Kali Linux tools** (optional) — nmap, gobuster, ffuf, sqlmap, testssl, etc. Only needed for network/infrastructure testing\n\n### Docker Setup (Recommended)\n\nA single script spins up a Kali Linux container with Claude Code, Playwright (headed via Xvfb), and all Kali security tools pre-installed:\n\n```bash\nbash scripts/kali-claude-setup.sh projects/pentest\n```\n\nThis builds a Docker image with Kali Rolling + Node.js + Claude Code + Playwright + Chromium, mounts the project workspace, and launches Claude Code with `--dangerously-skip-permissions`. Use `--rebuild` to force a fresh image build.\n\n---\n\n## Quick Start\n\n### 1. Clone and enter the project\n\n```bash\ngit clone https://github.com/transilienceai/communitytools.git\ncd communitytools/projects/pentest\n```\n\n### 2. Open Claude Code and run skills\n\n```bash\nclaude    # Launch Claude Code from the projects/pentest directory\n```\n\nThen use slash commands inside the Claude session:\n\n```\nPentest https://target.com            # Full penetration test (skills/coordination/)\n/hackthebox                          # HackTheBox challenge automation\n/hackerone                           # Bug bounty workflow\n/techstack-identification            # Passive tech stack recon\n/reconnaissance target.com           # Attack surface mapping\n/source-code-scanning ./app          # Static code analysis\n```\n\n---\n\n## Skills\n\nAll canonical skill and tool definitions live at the **repo root** (`skills/`, `tools/`). Each project under `projects/` symlinks only the ones it needs — see [Repository Structure](#repository-structure) for details.\n\nAgent roles (coordinator, executor, validator) are defined in `skills/coordination/` with reference material in `skills/coordination/reference/`, spawned dynamically via `Agent(prompt=...)`.\n\n### Skills by Category (26)\n\n#### Vulnerability Testing (10)\n\n| Skill | Coverage |\n|-------|----------|\n| `/injection` | SQL, NoSQL, OS Command, SSTI, XXE, LDAP/XPath |\n| `/client-side` | XSS (Reflected/Stored/DOM), CSRF, Clickjacking, CORS, Prototype Pollution |\n| `/server-side` | SSRF, HTTP Smuggling, Path Traversal, File Upload, Deserialization, Host Header |\n| `/authentication` | Auth Bypass, JWT, OAuth, Password Attacks, 2FA Bypass, CAPTCHA Bypass |\n| `/api-security` | GraphQL, REST API, WebSockets, Web LLM |\n| `/web-app-logic` | Business Logic, Race Conditions, Access Control, Cache Poisoning/Deception, IDOR |\n| `/cloud-containers` | AWS, Azure, GCP, Docker, Kubernetes |\n| `/system` | Active Directory, Privilege Escalation (Linux/Windows), Exploit Development |\n| `/infrastructure` | Port Scanning, DNS, MITM, VLAN Hopping, IPv6, SMB/NetBIOS |\n| `/social-engineering` | Phishing, Pretexting, Vishing, Physical Security |\n\n#### Reconnaissance (3)\n\n| Skill | Purpose |\n|-------|---------|\n| `/reconnaissance` | Subdomain discovery, port scanning, endpoint enumeration, API discovery, attack surface mapping |\n| `/osint` | Repository enumeration, secret scanning, git history analysis, employee footprint |\n| `/techstack-identification` | Passive tech stack inference across 17 intelligence domains |\n\n#### Specialized (5)\n\n| Skill | Purpose |\n|-------|---------|\n| `/ai-threat-testing` | OWASP LLM Top 10 — prompt injection, model extraction, data poisoning, supply chain |\n| `/blockchain-security` | Smart contract security, EVM storage, delegatecall, CREATE/CREATE2, DeFi exploits |\n| `/cve-poc-generator` | CVE research, NVD lookup, safe Python PoC generation, vulnerability reports |\n| `/dfir` | Digital forensics, incident response, Windows event logs, PCAP analysis, AD attack detection |\n| `/source-code-scanning` | SAST — OWASP Top 10, CWE Top 25, dependency CVEs, hardcoded secrets |\n\n#### Platform Integrations (2)\n\n| Skill | Purpose |\n|-------|---------|\n| `/hackerone` | Scope CSV parsing, parallel asset testing, PoC validation, platform-ready submissions |\n| `/hackthebox` | Playwright-based login, challenge browsing, VPN management, automated solving |\n\n#### Tooling (6)\n\n| Skill | Purpose |\n|-------|---------|\n| `/essential-tools` | Burp Suite, Playwright automation, methodology, reporting standards |\n| `/patt-fetcher` | On-demand payload extraction from PayloadsAllTheThings |\n| `/script-generator` | Optimized, syntax-validated script generation |\n| `formats/transilience-report-style` | Transilience-branded PDF report generation (ReportLab) |\n| `/github-workflow` | Git branching, commits, PRs, issues, code review |\n| `/skill-update` | Skill scaffolding, validation, GitHub workflow automation |\n\n### Tool Integrations (3)\n\n| Tool | Purpose |\n|------|---------|\n| **Playwright** | Browser automation for client-side testing via MCP |\n| **Kali Linux Tools** | nmap, masscan, nikto, gobuster, ffuf, sqlmap, testssl, and more |\n| **NVD / CVE Risk Score** | Auto-invoked CVE lookup (`/cve-risk-score`) — CVSS score, severity, CWE from NVD |\n\n### MCP Servers\n\nLocal Model Context Protocol servers that expose Transilience APIs to MCP-capable clients (Claude Desktop, Cline, Zed, etc.). Each server is self-contained under `mcp/<name>/` with its own `pyproject.toml` and install instructions.\n\n| Server | Purpose |\n|--------|---------|\n| [`mcp/transilience-vuln`](./mcp/transilience-vuln) | Single-CVE and bulk CVE enrichment (CVSS, EPSS, KEV, impact taxonomy, vendor advisories) via the Transilience Vulnerability API. |\n\n---\n\n## Architecture\n\nThe suite uses a **skills-only** architecture with canonical definitions at the repo root, symlinked into isolated project environments:\n\n- **Skills** (`skills/` at root, symlinked into each project's `.claude/skills/`) — User-triggered workflows invoked with `/skill-name`. Each skill contains a `SKILL.md` definition and `reference/` directory with attack techniques, cheat sheets, payloads, and agent role prompts.\n- **Coordination** (`skills/coordination/`) — Defines the 3 agent roles (coordinator, executor, validator) as a skill with role-based context injection. Read at runtime and passed to `Agent(prompt=...)`.\n- **Tools** (`tools/` at root, symlinked into each project's `.claude/tools/`) — Utility scripts for environment reading, integrations.\n\n### Multi-Agent Execution Flow\n\n```mermaid\nsequenceDiagram\n    participant User\n    participant Coord as Coordinator (inline)\n    participant Roles as Role Definitions (skills/coordination/)\n    participant Agents as Spawned Agents\n    participant Output as Standardized Outputs\n\n    User->>Coord: Pentest https://target.com\n    Coord->>Roles: Read skills/coordination/SKILL.md\n    Coord->>Coord: Execute coordinator workflow inline\n\n    Coord->>Roles: Read skills/coordination/reference/executor-role.md\n    Coord->>Agents: Agent(prompt=executor_role + chain + skills) × N\n    Note over Agents: SQL/XSS/SSRF/JWT/OAuth/SSTI/XXE...\n    Agents-->>Output: findings/*.json + evidence/*.png\n\n    Coord->>Roles: Read skills/coordination/reference/validator-role.md\n    Coord->>Agents: Agent(prompt=validator_role + evidence ONLY) × N\n    Note over Agents: Blind review — no attack chain context\n    Agents-->>Output: validated/*.json\n\n    Coord->>Output: Phase 6: Generate reports\n    Output-->>User: Executive + technical reports\n```\n\n### Repository Structure\n\n```\ncommunitytools/\n├── CLAUDE.md                        # Project instructions\n├── marketplace.json                 # Machine-readable project manifest\n├── papers/                          # Research papers\n├── benchmarks/                      # XBOW benchmark runner\n│\n├── skills/                          # ← Canonical skill definitions (source of truth)\n│   ├── coordination/               # ← Agent roles + coordination reference\n│   │   ├── SKILL.md                # Coordinator logic (entry point)\n│   │   └── reference/\n│   │       ├── executor-role.md    # Executor role prompt\n│   │       ├── validator-role.md   # Validator role prompt (blind review)\n│   │       ├── context-injection.md # What context each role receives\n│   │       ├── ATTACK_INDEX.md     # 53 attack types mapped to skills\n│   │       ├── OUTPUT_STRUCTURE.md # Engagement output directory spec\n│   │       ├── VALIDATION.md       # 5-check finding validation framework\n│   │       ├── GIT_CONVENTIONS.md  # Branch/commit/PR standards\n│   │       └── PATT_STANDARD.md    # PayloadsAllTheThings integration\n│   ├── injection/\n│   │   ├── SKILL.md\n│   │   └── reference/\n│   ├── reconnaissance/\n│   ├── server-side/\n│   └── ...                          # 27 skill directories total\n│\n├── tools/                           # ← Canonical tool integrations (source of truth)\n│   ├── env-reader.py\n│   └── slack-send.py\n│\n└── projects/                        # ← Isolated project environments\n    └── pentest/\n        └── .claude/\n            ├── skills/              # Real directory, contents are symlinks\n            │   ├── injection/ → ../../../../skills/injection/\n            │   └── ...              # Each project picks what it needs\n            └── tools/               # Real directory, contents are symlinks\n                ├── env-reader.py → ../../../../tools/env-reader.py\n                └── ...\n```\n\n### Why This Structure?\n\n**Canonical root directories** (`skills/`, `tools/`) hold the single source of truth for all definitions. No duplication, no drift.\n\n**Project directories** (`projects/`) are isolated environments designed to be run independently with `claude` from within the project folder. Each project has its own `.claude/` directory with real `skills/` and `tools/` folders — but the contents are **symlinks** pointing back to the canonical sources.\n\nThis design gives you:\n\n- **Isolation** — Each project is a self-contained working directory. Run `claude` from `projects/pentest/` and it discovers only the skills that project has symlinked.\n- **Single source of truth** — Edit a skill once in `skills/`, and every project that symlinks it gets the update immediately.\n- **Selective inclusion** — A new project doesn't need all 23 skills. Symlink only what's relevant.\n- **Claude Code compatibility** — Claude Code resolves symlinks transparently via the OS.\n\n**Adding a new project:**\n\n```bash\nmkdir -p projects/myproject/.claude/{skills,tools}\ncd projects/myproject/.claude/skills\n\n# Symlink only the skills this project needs\nln -s ../../../../skills/injection injection\n# Coordination is a skill like any other — symlink if needed\nln -s ../../../../skills/coordination coordination\nln -s ../../../../skills/reconnaissance reconnaissance\n# ... add more as needed\n\n# Same for tools\ncd ../tools\nln -s ../../../../tools/env-reader.py env-reader.py\n```\n\n---\n\n## Contributing\n\nWe welcome contributions from the security community!\n\n**Read the full guide:** [CONTRIBUTING.md](CONTRIBUTING.md)\n\n**Quick path using Skill Update:**\n```bash\n/skill-update\n# Select: CREATE → provide details → automated GitHub workflow\n# Handles: issue creation, branch, skill generation, validation, commit, PR\n```\n\n---\n\n## Security & Legal\n\n**IMPORTANT: These tools are designed for authorized security testing ONLY.**\n\n**Authorized & Legal Use:**\n- Penetration testing with written authorization\n- Bug bounty programs within scope\n- Security research on your own systems\n- CTF competitions and training environments\n- Educational purposes with proper permissions\n\n**Prohibited & Illegal Use:**\n- Unauthorized testing of any systems\n- Malicious exploitation of vulnerabilities\n- Data theft or system disruption\n- Any use that violates local or international laws\n\n**Users are solely responsible for compliance with all applicable laws and regulations.**\n\n### Responsible Disclosure\n\nIf you discover a vulnerability using these tools:\n1. Do not exploit beyond proof-of-concept\n2. Report immediately to the vendor/organization\n3. Follow responsible disclosure timelines (typically 90 days)\n4. Document thoroughly for remediation\n\n---\n\n## Community & Support\n\n- [GitHub Discussions](https://github.com/transilienceai/communitytools/discussions) — Ask questions, share ideas\n- [GitHub Issues](https://github.com/transilienceai/communitytools/issues) — Report bugs, request features\n- [Transilience.ai](https://www.transilience.ai) — See what else we're building\n- [LinkedIn](https://linkedin.com/company/transilienceai) — Follow our work\n- [Email](mailto:contact@transilience.ai) — Get in touch\n\n---\n\n## Project Stats\n\n| Category | Count |\n|----------|-------|\n| **Skills** | 27 |\n| **Role Prompts** | 3 (in coordination skill) |\n| **Tool Integrations** | 3 |\n| **Attack Types** | 53 |\n| **Reference Files** | 160+ |\n\n**Coverage:**\n- OWASP Top 10 (2021) — 100%\n- OWASP LLM Top 10 (2025) — 100%\n- SANS Top 25 CWE — 90%+\n- MITRE ATT&CK TTPs — mapped for all findings\n\n---\n\n## License\n\nMIT License — Copyright (c) 2026 Transilience AI. See [LICENSE](LICENSE) for details.\n\n---\n\n## Contributors\n\n<a href=\"https://github.com/transilienceai/communitytools/graphs/contributors\">\n  <img src=\"https://contrib.rocks/image?repo=transilienceai/communitytools\" />\n</a>\n\n---\n\n<div align=\"center\">\n\n**Built by [Transilience AI](https://www.transilience.ai)**\n\nWe build AI-driven cloud security and compliance automation. These open-source tools reflect how we think about security — if you're curious about the platform behind them, [take a look](https://www.transilience.ai).\n\n[![Star this repository](https://img.shields.io/badge/Star%20this%20repo-yellow?style=for-the-badge)](https://github.com/transilienceai/communitytools)\n\n[Website](https://www.transilience.ai) | [Issues](https://github.com/transilienceai/communitytools/issues) | [Discussions](https://github.com/transilienceai/communitytools/discussions)\n\n`claude-code` `ai-security` `penetration-testing` `bug-bounty` `owasp` `llm-security` `ai-threat-testing` `security-automation` `ethical-hacking` `cybersecurity` `appsec` `web-security` `hackerone` `hackthebox` `multi-agent`\n\n</div>\n",
  "bytes": 16859,
  "sha": "a8c575c3a0c5c32f4bae85006f389fd157fbb7a63cc45c9caf860b5800e1fe3c",
  "repo_slug": "transilienceai/communitytools",
  "fonte": "repo",
  "truncated": false,
  "api": "https://api.agentalog.com/api/listings/skl_transilienceai_communitytools_social_eng_feb3f09c/readme"
}