essential-tools

v2026.09.24

Core pentesting tools and methodology - Burp Suite usage, Playwright automation, binary analysis, testing methodology, and professional reporting standards.

GitHub
安装命令
npx skhub add transilienceai/essential-tools
Markdown
SKILL.md

Essential Tools

Core tools, methodology, and reporting standards for penetration testing.

Components

ComponentPurpose
Burp SuiteProxy, scanner, intruder, repeater, sequencer
PlaywrightBrowser automation, evidence capture, SPA testing
Binary AnalysisStatic analysis, reverse engineering, string extraction
NucleiTemplated exposure & misconfiguration scanning
sslscanTLS posture (protocols, ciphers, cert)
MethodologyPTES, OWASP WSTG, attack prioritization
ReportingProfessional report templates, PDF generation

Reference

  • reference/essential-skills*.md - Burp Suite techniques and web security testing methodology
  • reference/playwright-automation.md - Playwright MCP usage for pentesting
  • reference/binary-analysis-quickstart.md - Static analysis for executable files and reverse engineering
  • reference/web-application-attacks.md - Web application attack methodology
  • formats/transilience-report-style/pentest-report.md - Finding quality standards, compliance mapping, and pre-delivery checklist

Required-at-start tooling (web/API engagements)

Run an availability check before declaring recon complete:

command -v subfinder nuclei sslscan httpx; curl -s "https://crt.sh/?q=%25.${DOMAIN}&output=json" | head -c1

  • Subdomain/CT enum: subfinder, certspotter, crt.sh
  • TLS posture: sslscan
  • Templated exposure: nuclei

If a tool-class is unavailable, record it as an explicit limitation — NEVER declare recon COMPLETE having skipped a whole class. Hand-rolled urllib is not a substitute (see skills/coordination/reference/principles.md 'Real tools before hand-rolled HTTP').

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

Sep 24, 2026

分类

未分类

许可证

MIT

源路径

skills/essential-tools

默认分支

main

最新提交

95fdc12

Tree SHA

854bd03