0x0pointer0x0pointerOfficialยท4 Agent Skills Included

agent-smith

Autonomous penetration testing, exploit chaining, and verified security reporting

Runs full penetration tests from recon through exploitation using 50+ sandboxed scanners like nmap, nuclei, sqlmap, and Metasploit. Chains specialized workflows for web apps, APIs, cloud, Active Directory, codebases, and LLM red-teaming without manual orchestration. Verifies every finding with proof-of-concept artifacts, out-of-band callbacks, and source traces, then generates reports, patches, and CVE packages.
npx skills add 0x0pointer/agent-smith --all -g -y
Available:

Instructs the agent on how to call the five consolidated MCP security tools, invoke and chain pentest skills per client, and log findings, coverage, and decisions during a scan.

All Skills in This Repository (4)

Pure Emerald Level Indicators

Frequently Asked Questions

FAQPage Schema
How to install agent-smith?โ–ผ

Run `npx skills add 0x0pointer/agent-smith --all -g -y` in your terminal to install all skills globally. Docker Desktop and one supported LLM client are required.

What does agent-smith do?โ–ผ

It runs autonomous or human-guided penetration tests, chaining 35+ security skills from recon to exploitation and producing verified findings, PoCs, patches, and CVE packages.

Which LLM clients work with agent-smith?โ–ผ

It works with Claude Code, OpenAI Codex, OpenCode, and any MCP-capable client, including fully local models via Ollama or vLLM.

Can agent-smith test web apps and APIs?โ–ผ

Yes. Skills like /web-exploit, /param-fuzz, and /business-logic systematically test injection, auth, and logic flaws, with a coverage matrix tracking every endpoint and parameter.

Is agent-smith safe to run on any target?โ–ผ

Only use it on systems you own or have written permission to test. All scanners run in sandboxed Docker containers with enforced cost, time, and call limits.

Related Repositories in Software Engineering

View All in Software Engineeringโ†’