{"id":"73f3c4e4-84b4-4bb9-b911-38c88dfea1b9","slug":"jumbo-wjb-pentest-skills","name":"pentest-tool","description":"Autonomous penetration testing framework. Claude acts as offensive security expert with independent decision-making. Provides methodology and principles, not command scripts. ALL commands must execute in kali-pentest container via 'docker exec kali-pentest <tool>'.","canonicalUrl":"https://www.xpersona.co/skill/jumbo-wjb-pentest-skills","sourceUrl":"https://github.com/Jumbo-WJB/pentest-skills","homepage":null,"source":"GITHUB_OPENCLEW","vendor":{"slug":"jumbo-wjb","label":"Jumbo Wjb","url":"https://github.com/Jumbo-WJB/pentest-skills"},"protocols":["OPENCLEW"],"capabilities":["this","returns","for","spring","i"],"trustScore":null,"trustConfidence":"unknown","artifactCount":0,"benchmarkCount":0,"lastRelease":null,"freshnessAt":"2026-04-15T04:13:23.689Z","freshnessLabel":"Apr 15, 2026","securityReviewed":true,"openapiReady":false,"stats":[{"label":"Trust score","value":"Unknown"},{"label":"Compatibility","value":"OpenClaw"},{"label":"Freshness","value":"Apr 15, 2026"},{"label":"Vendor","value":"Jumbo Wjb"},{"label":"Artifacts","value":"0"},{"label":"Benchmarks","value":"0"},{"label":"Last release","value":"Unpublished"}],"factsPreview":[{"factKey":"docs_crawl","label":"Crawlable docs","value":"6 indexed pages on the official domain","category":"integration","href":"https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar","sourceUrl":"https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar","sourceType":"search_document","confidence":"medium","observedAt":"2026-04-15T05:03:46.393Z","isPublic":true,"metadata":{}},{"factKey":"vendor","label":"Vendor","value":"Jumbo Wjb","category":"vendor","href":"https://github.com/Jumbo-WJB/pentest-skills","sourceUrl":"https://github.com/Jumbo-WJB/pentest-skills","sourceType":"profile","confidence":"medium","observedAt":"2026-04-15T04:13:23.689Z","isPublic":true,"metadata":{}},{"factKey":"protocols","label":"Protocol compatibility","value":"OpenClaw","category":"compatibility","href":"https://www.xpersona.co/api/v1/agents/jumbo-wjb-pentest-skills/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/jumbo-wjb-pentest-skills/contract","sourceType":"contract","confidence":"medium","observedAt":"2026-04-15T04:13:23.689Z","isPublic":true,"metadata":{}},{"factKey":"traction","label":"Adoption signal","value":"19 GitHub stars","category":"adoption","href":"https://github.com/Jumbo-WJB/pentest-skills","sourceUrl":"https://github.com/Jumbo-WJB/pentest-skills","sourceType":"profile","confidence":"medium","observedAt":"2026-04-15T04:13:23.689Z","isPublic":true,"metadata":{}},{"factKey":"handshake_status","label":"Handshake status","value":"UNKNOWN","category":"security","href":"https://www.xpersona.co/api/v1/agents/jumbo-wjb-pentest-skills/trust","sourceUrl":"https://www.xpersona.co/api/v1/agents/jumbo-wjb-pentest-skills/trust","sourceType":"trust","confidence":"medium","observedAt":null,"isPublic":true,"metadata":{}}],"highlights":["19 GitHub stars","Trust evidence available"],"agentCard":{"name":"pentest-tool","description":"Autonomous penetration testing framework. Claude acts as offensive security expert with independent decision-making. Provides methodology and principles, not command scripts. ALL commands must execute in kali-pentest container via 'docker exec kali-pentest <tool>'.","source":"GITHUB_OPENCLEW","sourceId":"github:1122655387","repository":"https://github.com/Jumbo-WJB/pentest-skills","documentation":"https://www.xpersona.co/skill/jumbo-wjb-pentest-skills/agent/jumbo-wjb-pentest-skills","protocols":["OPENCLEW"],"capabilities":["this","returns","for","spring","i"],"languages":["typescript"],"install":{"command":"git clone https://github.com/Jumbo-WJB/pentest-skills.git","ecosystem":"git"},"examples":[{"kind":"example","language":"text","snippet":"Run: nikto -h <url>\nThen: sqlmap -u <url>\nThen: gobuster dir -u <url>"},{"kind":"example","language":"text","snippet":"[Claude's Internal Reasoning]\n1. What type of web app is this? Let me fingerprint first\n   → Choose: whatweb/wappalyzer/manual inspection\n   \n2. Based on tech stack, what vulnerabilities are likely?\n   - PHP? → Consider LFI, RCE, SQLi\n   - WordPress? → Plugin vulns, wp-admin brute-force\n   - Apache Struts? → Known CVEs\n   \n3. Select tools that match the discovered attack surface\n   → If database-driven: SQLi testing priority\n   → If file uploads exist: Shell upload vectors\n   → If authentication: Brute-force/bypass attempts\n\n4. After each test, evaluate results:\n   - Found SQLi? Deepen database exploitation\n   - No results? Try alternative vectors (XSS, CSRF, logic flaws)"}]}}