By HarshXor
Professional Web Application Penetration Testing Plugin with 7-phase PTES workflow, 100+ OWASP WSTG tests, and Burp Suite integration
Import and process data from Burp Suite — parse scan results, proxy history, and issue reports into the pentest project
PTES Phase 5 — develop proof-of-concept exploits for confirmed vulnerabilities and assess true business impact
PTES Phase 7 — generate a professional penetration testing report with executive summary, technical findings, and remediation guidance
PTES Phase 2 — map the full attack surface through network enumeration, web crawling, technology detection, and static analysis
Start a new PTES-aligned penetration testing engagement — define scope, objectives, and rules of engagement
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
A comprehensive Claude plugin for professional-grade web application penetration testing, fully aligned with the Penetration Testing Execution Standard (PTES) and OWASP Web Security Testing Guide (WSTG).
/ptes-start
This will guide you through pre-engagement activities and create a standardized project structure.
1. /ptes-start → Define scope and objectives
2. /intelligence-gathering → Map attack surface
3. /threat-modeling → Analyze attack vectors
4. /vulnerability-scan → Execute OWASP WSTG tests
5. /burp-import → Import Burp Suite data
6. /execute-exploitation → Develop PoCs
7. /generate-report → Create professional report
/ptes-start Start new penetration testing project
/define-scope Define target and scope
/establish-roe Document rules of engagement
/create-project-structure Initialize directory structure
/intelligence-gathering Execute reconnaissance
/scan-infrastructure Perform port/service scanning
/enumerate-endpoints Discover all endpoints
/identify-technology Detect technology stack
/analyze-static-content Extract static information
/vulnerability-scan Execute OWASP WSTG tests
/cvss-calculator Calculate CVSS v3.1 scores
/cwe-mapper Map findings to CWE IDs
/burp-import Import Burp Suite findings
/execute-exploitation Develop proof of concepts
/payload-engineer Create custom payloads
/test-exploitability Validate vulnerability impact
/chain-vulnerabilities Develop attack chains
/post-exploitation Assess persistence opportunities
/lateral-movement-test Test lateral movement
/data-access-validation Verify sensitive data access
/generate-report Create full pentesting report
/export-findings Export findings data
/create-executive-summary Create summary for stakeholders
| Standard | Status | Details |
|---|---|---|
| PTES | ✅ Full Alignment | All 7 phases implemented |
| OWASP WSTG | ✅ Full Coverage | 100+ test cases |
| CVSS v3.1 | ✅ Supported | Accurate scoring |
| CWE | ✅ Mapped | All findings mapped |
| NIST SP 800-115 | ✅ Aligned | Technical testing |
| ISO 27001 | ✅ Compatible | Risk-based approach |
Generated projects follow this structure:
npx claudepluginhub harshxor/claude-vibe-pentesting --plugin claude-vibe-pentestingTools to maintain and improve CLAUDE.md files - audit quality, capture session learnings, and keep project memory current.
Comprehensive feature development workflow with specialized agents for codebase exploration, architecture design, and quality review
Browser automation and end-to-end testing MCP server by Microsoft. Enables Claude to interact with web pages, take screenshots, fill forms, click elements, and perform automated browser testing workflows.
A growing collection of Claude-compatible academic workflow bundles. Covers scientific figures, manuscript writing and polishing, reviewer assessment, citation retrieval, data availability, paper reading, literature search, response letters, paper-to-PPTX conversion, and evidence-grounded Chinese invention patent drafting. Rules are organized as reusable skill folders with explicit workflows and quality checks.
Harness-native ECC operator layer - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses
Real-time statusline HUD for Claude Code - context health, tool activity, agent tracking, and todo progress