.skills
SkillSecurityGives your agent guidance for running an AI-powered penetration-testing framework that scans systems for vulnerabilities.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the .skills skill
About this skill
π‘βοΈAI-Powered Penetration Testing Framework with automated vulnerability scanning, multi-agent system, and compliance reportingπ‘βοΈ
What this skill tells your AI
The instructions your AI receives, as published by shadd0wtaka/zen-ai-pentest in .skills/SKILL.md and read by ahelβs review.
Projekt-Γbersicht
Zen-AI-Pentest ist ein autonomes, KI-gesteuertes Penetration-Testing-Framework mit:
- 1206+ Dateien, 179MB Repository
- 58 GitHub Actions Workflows
- 20+ integrierte Sicherheitstools
- Multi-Agent-Architektur mit ReAct Pattern
- FastAPI-Backend mit WebSocket-Support
- React-Dashboard fΓΌr Web-UI
Architektur
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β FRONTEND (React + TypeScript + Tailwind) β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β API LAYER (FastAPI + WebSocket + JWT Auth) β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β AUTONOMOUS LAYER (ReAct Agent + Memory + Tool Exec) β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β RISK ENGINE (CVSS + EPSS + False Positive Reduction) β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β TOOLS LAYER (Nmap, SQLMap, Metasploit, etc.) β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β DATA LAYER (PostgreSQL + SQLite + Redis) β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Kritische Issues (P0)
- Command Injection Risk -
tool_executor.pynutztsubprocess_shellstattsubprocess_exec - Variable Bug -
react_agent_vm.py:config.vm_usernamesollteself.vm_config.vm_usernamesein - Hardcoded Credentials - Default-Credentials in API auth fallback
- SSL Verification Disabled - Mehrere Tools haben
verify=False
Module-Γbersicht
Core (core/)
orchestrator.py- ZenOrchestrator, Hauptkoordinatorplugin_manager.py- Plugin-Systemrate_limiter.py- Rate Limitingcache.py- Multi-Tier Cachingshield_integration.py- Zen Shield Integration
Agents (agents/)
react_agent.py- ReAct Pattern Implementierungreact_agent_enhanced.py- Erweiterter ReAct Agentreact_agent_vm.py- VM-basierter Agentagent_orchestrator.py- Agent-Koordination- Spezialisierte Agents:
research_agent,analysis_agent,exploit_agent
Autonomous (autonomous/)
agent_loop.py- State Machine (IDLE β PLANNING β EXECUTING β OBSERVING β REFLECTING β COMPLETED)tool_executor.py- Tool-AusfΓΌhrung mit Safety-Levelsexploit_validator.py- Sandbox-Validierungmemory.py- LangGraph Memory Integrationreact.py- ReAct Core Loop
Risk Engine (risk_engine/)
false_positive_engine.py- Bayes'sche Filter + Multi-LLM Votingbusiness_impact_calculator.py- Finanzielle/Compliance-Auswirkungencvss.py- CVSS 3.1 Calculatorepss.py- EPSS Client
API (api/)
main.py- FastAPI Appauth.py- JWT Authenticationroutes/- 50+ API Endpunktewebsocket.py+websocket_v2.py- Real-time Updates
Tools (tools/)
- Network:
nmap_integration.py(fehlt!),masscan_integration.py,scapy_integration.py - Web:
sqlmap_integration.py,gobuster_integration.py,burpsuite_integration.py - Exploit:
metasploit_integration.py,hydra_integration.py - AD:
bloodhound_integration.py,crackmapexec_integration.py,responder_integration.py
Memory (memory/)
- 4-Layer Architecture: Working β Short-term β Long-term β Vector Store
- Backends: SQLite, Redis
- LangGraph Integration
CI/CD Workflows (58 total)
Kritische Workflows:
ci.yml- Haupt-CIsecurity.yml- Sicherheits-Scanscode-quality.yml- Linting & Formattingpr-validation.yml- PR Checksrelease.yml- Release-Prozessdeploy.yml- Deployment
Auto-Workflows:
dependabot-auto-merge.yml- Automatische Dependency-Updatesauto-fix-repository.yml- Automatische Fixeshealth-check.yml- Repository-Health
Entwicklungs-Standards
Code Style
- Black: Line length 127
- isort: Profile "black"
- Ruff: E, F, W rules
- mypy: Type checking (optional)
Testing
- pytest mit asyncio-UnterstΓΌtzung
- Coverage-Target: 70%
- Security-Tests: Bandit, Safety
Security
- Alle Dependencies auf CVE-Versionen prΓΌfen
- Keine Hardcoded Secrets
- Input-Validierung mit
input_validator.py - Zen Shield fΓΌr Output-Sanitization
Wichtige Befehle
# Setup
pip install -e ".[dev]"
# Tests
pytest --cov=. --cov-report=html
# Linting
black .
isort .
flake8
# Security
bandit -r .
safety check
# API starten
uvicorn api.main:app --reload
# Docker
docker-compose up -d
Versions-Inkonsistenzen (zu fixen)
setup.py: Version 2.3.9 βpyproject.toml: Version 2.3.9README.md: Version 2.3.9 βaction.yml: Version 2.3.9
Empfohlene Version: 2.3.9
Signals
- GitHub stars
- 469
- Forks
- 81
- Last commit
- Sep 2026
ahel review
K1binfo
installs-packages
Automated review, not a security audit. Ruleset v1+k2.
Advanced
- Item type
- skill
- Key
skills-shadd0wtaka- Source
- github.com/shadd0wtaka/zen-ai-pentest