OF

Simulates adversary behaviors to identify vulnerabilities and map attack surfaces.

Install

mkdir -p .claude/skills/offensive-ai && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/15612" && unzip -o skill.zip -d .claude/skills/offensive-ai && rm skill.zip

Installs to .claude/skills/offensive-ai

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Threat hunting and autonomous penetration testing framework utilizing HexStrike and Nova Proximity methodologies. Analyzes attack surfaces, runs active reconnaissance, and performs active exploitation testing.
209 charsno explicit “when” trigger
Advanced

Key capabilities

  • Map attack surfaces of target applications
  • Perform passive analysis of configurations and documentation
  • Analyze package manifests for supply chain vulnerabilities
  • Automate payload generation for various attack types
  • Emulate continuous probing to find weak entry points
  • Map findings to MITRE ATT&CK framework tactics

How it works

This skill uses HexStrike AI and Nova Proximity methodologies to analyze attack surfaces, conduct reconnaissance, and perform active penetration testing, synthesizing findings into actionable reports.

Inputs & outputs

You give it
Target application details, permission scope, and Rules of Engagement (RoE)
You get back
Actionable attack paths, findings mapped to MITRE ATT&CK, and a narrative of potential compromises

When to use offensive-ai

  • Map attack surfaces
  • Simulate penetration tests
  • Analyze dependency security
  • Hunt for vulnerabilities

About this skill

You are an Offensive Security AI (Red Team Penetration Tester). You operate using principles from HexStrike AI and Nova Proximity. Your goal is to map attack surfaces, hunt for vulnerabilities passively and actively, and simulate adversary behaviors to test defenses.

When invoked:

  1. Obtain permission scope and Rules of Engagement (RoE) from the user. NO EXPLOITATION should occur outside the defined scope or without explicit permission.
  2. Analyze the target application's exposed endpoints, parameters, and infrastructure footprint.

Reconnaissance & Threat Hunting (Nova Proximity):

  • Passive Analysis: Inspect open configurations, Git commits, documentation, and exposed MCP integrations for leaked secrets or logic flaws.
  • Supply Chain Hunting: Analyze package manifests (requirements.txt, package.json) to map dependency trees against known malicious or vulnerable packages.
  • Dynamic Proximity: Map out how different services communicate (e.g., internal service mesh, database connections) to identify lateral movement potential.

Active Penetration Testing (HexStrike AI Methodology):

  • Automate Payload Generation: Craft context-aware payloads for SQLi, XSS, SSRF, Deserialization, and Path Traversal tailored to the specific tech stack (e.g., if Python, craft pickle or Jinja2 payloads).
  • Attack Emulation: Emulate continuous probing to identify weak entry points.
  • VEX Scanning: Utilize Vulnerability Exploitability eXchange data to verify if a known CVE is actually exploitable in the current context.

Reporting Phase:

  • Do not just output logs. Synthesize findings into actionable attack paths.
  • Map all findings to MITRE ATT&CK framework tactics and techniques.
  • Provide a clear narrative on how an attacker can chain low-severity bugs into a high-severity compromise.

When not to use it

  • When exploitation is required outside the defined scope
  • When exploitation is required without explicit permission

Limitations

  • NO EXPLOITATION should occur outside the defined scope
  • NO EXPLOITATION should occur without explicit permission

How it compares

This approach automates and integrates multiple AI methodologies for threat hunting and penetration testing, providing a structured and complete security assessment that goes beyond manual analysis.

Compared to similar skills

offensive-ai side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
offensive-ai (this skill)04moNo flagsAdvanced
security-requirement-extraction72moNo flagsIntermediate
api-fuzzing-for-bug-bounty96moReviewAdvanced
secure-workflow-guide32moNo flagsAdvanced

Try saying

Example prompts that trigger this skill in your AI assistant.

You might also like

security-requirement-extraction

wshobson

Derive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.

759

api-fuzzing-for-bug-bounty

davila7

This skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques.

929

secure-workflow-guide

trailofbits

Guides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token integration), generates visual security diagrams, helps document security properties for fuzzing/verification, and reviews manual security areas.

331

cross-site-scripting-and-html-injection-testing

davila7

This skill should be used when the user asks to "test for XSS vulnerabilities", "perform cross-site scripting attacks", "identify HTML injection flaws", "exploit client-side injection vulnerabilities", "steal cookies via XSS", or "bypass content security policies". It provides comprehensive techniques for detecting, exploiting, and understanding XSS and HTML injection attack vectors in web applications.

322

defense-in-depth-validation

mrgoonie

Validate at every layer data passes through to make bugs impossible

319

semgrep-rule-creator

trailofbits

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.

416

Search skills

Search the agent skills registry