brucesongsbrucesongsCommunityยท72 Agent Skills Included

kali-claw

Penetration testing across 139 security domains on Kali Linux

Executes full penetration testing workflows across 139 security domains, from web exploitation and cloud attacks to mainframe, 5G telecom, and AI red teaming. Eliminates manual tool selection and methodology guesswork with structured payloads, test cases, and defense guidance for every domain. Coordinates attacker, defender, and auditor roles into unified engagement reports with evidence tracking.
npx skills add brucesongs/kali-claw --all -g -y
Available:

Instructs the agent to load its hacker identity and memory files at session start, follow the 12 hacker laws, and orchestrate attacker, defender, and auditor roles across phased penetration testing engagements.

All Skills in This Repository (72)

Pure Emerald Level Indicators
๐Ÿ“ฆ In Repo
brucesongsbrucesongs

security-misconfiguration

Detect and remediate security misconfigurations across web, cloud, and container deployments.

Community
Advanced
๐Ÿ“ฆ In Repo
brucesongsbrucesongs

knowledge-ops

Transform session findings into persistent knowledge graphs with linked relationships.

Community
Advanced
๐Ÿ“ฆ In Repo
brucesongsbrucesongs

web-xxe

Identify and exploit XML External Entity vulnerabilities in XML-processing endpoints.

Community
Advanced
๐Ÿ“ฆ In Repo
brucesongsbrucesongs

binary-reverse

Analyze compiled binaries with radare2 and Ghidra to identify vulnerabilities.

Community
Advanced
๐Ÿ“ฆ In Repo
brucesongsbrucesongs

multi-agent-collaboration

Coordinates multiple specialized agents for penetration testing via task decomposition and parallel execution.

Community
Advanced
๐Ÿ“ฆ In Repo
brucesongsbrucesongs

docker-patterns

Create reproducible Docker-based security labs with localhost-only bindings and isolation.

Community
Advanced
๐Ÿ“ฆ In Repo
brucesongsbrucesongs

detection-engineering

Create and validate Sigma rules, YARA signatures, and SIEM queries as code.

Community
Advanced
๐Ÿ“ฆ In Repo
brucesongsbrucesongs

crypto-attacks

Detect weak algorithms, padding, and key management flaws in TLS and JWT configurations.

Community
Advanced
๐Ÿ“ฆ In Repo
brucesongsbrucesongs

social-intelligence

Extract real-time social intelligence signals from Reddit, Hacker News, and X.

Community
Advanced
๐Ÿ“ฆ In Repo
brucesongsbrucesongs

autonomous-loops

Automate repetitive reconnaissance, scanning, and learning cycles across multiple targets.

Community
Advanced
๐Ÿ“ฆ In Repo
brucesongsbrucesongs

secret-management-attack

Map leaked credentials across code, containers, cloud, and CI/CD pipelines.

Community
Advanced
๐Ÿ“ฆ In Repo
brucesongsbrucesongs

council

Analyze security questions from attack, defense, and audit perspectives.

Community
Advanced

Frequently Asked Questions

FAQPage Schema
How to install kali-claw?โ–ผ

Run `npx skills add brucesongs/kali-claw --all -g -y` in your terminal to install all skills globally.

What security domains does kali-claw cover?โ–ผ

It covers 139 domains including web attacks (SQLi, XSS, SSRF, XXE), cloud and container security, Active Directory, binary reverse engineering, mainframe, 5G telecom, AI/LLM red teaming, and OSINT.

Does kali-claw work with Claude Code and Cursor?โ–ผ

Yes. Every skill follows the universal SKILL.md standard and runs in Claude Code, OpenClaw, Cursor, Windsurf, and Codex.

Can kali-claw run a full penetration test automatically?โ–ผ

Yes. Its orchestration scripts chain recon, scanning, exploitation, and reporting phases, with multi-agent attacker, defender, and auditor roles producing a unified report.

Does kali-claw include defensive guidance?โ–ผ

Yes. Every skill ships with a Defense Triple: a layered defense matrix, SIEM-ready detection rules (Sigma, Splunk SPL, Sysmon), and attacker evasion patterns.

Related Repositories in Software Engineering

View All in Software Engineeringโ†’