claude-pentest-framework
Warn
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install a plugin from the GitHub repository 'Stickman230/claude-pentest' and clone a remote server from 'Wh0am123/MCP-Kali-Server'. These sources are not recognized as trusted organizations or well-known services.
- [COMMAND_EXECUTION]: The framework's core workflow involves the automated generation and local execution of Python scripts ('poc.py') to demonstrate exploitation. It also utilizes 'Playwright' for browser-based automated testing.
- [PROMPT_INJECTION]: The skill performs reconnaissance and vulnerability testing on external websites and APIs. This ingestion of untrusted external content (HTML, HTTP responses) makes the agent vulnerable to indirect prompt injection, where an attacker could embed instructions to manipulate the penetration testing process.
Audit Metadata