AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Offensive Toolkit

skill-wang200935-security-agent-skills-offensive-toolkit · by Wang200935

Use hackingtool — a 21-category, 173-tool offensive security and pentesting

No reviews yet
0 installs
11 views
0.0% view→install

Install

$ agentstack add skill-wang200935-security-agent-skills-offensive-toolkit

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-wang200935-security-agent-skills-offensive-toolkit)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
20d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Offensive Toolkit? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

HackingTool — Offensive Security Suite

Purpose

hackingtool is a comprehensive offensive security toolkit (173 tools across 21 categories). Installed locally at ~/hackingtool/ in a venv; launcher at ~/.local/bin/hackingtool.

Installation Details

  • Source: git clone https://github.com/Z4nzu/hackingtool.git ~/hackingtool
  • Venv: ~/hackingtool/venv (Python 3.11, dependencies from requirements.txt)
  • Launcher: ~/.local/bin/hackingtool (bash, auto-activates venv, on PATH)
  • User config: ~/.hackingtool/config.json (toolsdir, gobin_dir, etc.)
  • macOS caveats: No brew on system PATH → pkg_mgr is empty; most tools need manual Homebrew installs. Wireless attacks (airgeddon, fluxion, etc.), AD/Linux-only tools, and hardware-dependent tools will fail to install but the TUI still works for discovery.

How to Interact

1. Interactive TUI (for the USER, not for Hermes)

hackingtool

This opens the Rich-based TUI. The user navigates with numbers, /query for search, t for tag filtering, r for task recommendations, ? for help, q to quit.

2. Programmatic Tool Listing (Hermes internal)

List categories and all tools:

~/hackingtool/venv/bin/python3 -c "
import sys; sys.path.insert(0, '~/hackingtool')
from hackingtool import all_tools
for cat in all_tools:
    print(cat.TITLE)
    if hasattr(cat, 'TOOLS'):
        for t in cat.TOOLS:
            print(f\"  {t.TITLE}\")
"

3. Search Tools by Keyword

~/hackingtool/venv/bin/python3 -c "
import sys; sys.path.insert(0, '~/hackingtool')
from hackingtool import _collect_all_tools
query = 'KEYWORD'.lower()
for tool, cat in _collect_all_tools():
    if query in tool.TITLE.lower() or query in (tool.DESCRIPTION or '').lower():
        print(f'{tool.TITLE}  [{cat}] — {tool.DESCRIPTION.splitlines()[0]}')
"

4. Filter by Tag

Tags: osint, recon, scanner, bruteforce, web, wireless, social-engineering, c2, privesc, network, credentials, forensics, reversing, cloud, mobile, active-directory, ddos, payload, crawler. To show tools matching a tag:

~/hackingtool/venv/bin/python3 -c "
import sys; sys.path.insert(0, '~/hackingtool')
from hackingtool import _get_all_tags
tag_index = _get_all_tags()
for tool, cat in tag_index.get('TAG_NAME', []):
    print(f'{tool.TITLE}  [{cat}]')
"

5. Get Task Recommendations

Common tasks and recommended tools come from hackingtool._RECOMMENDATIONS. For a task like "scan a network", it maps to tags like scanner, port-scanner. Use _get_all_tags() with those tags to show matching tools.

6. Install a Specific Tool (interactive, hands back to user)

~/hackingtool/venv/bin/python3 -c "
import sys; sys.path.insert(0, '~/hackingtool')
from hackingtool import all_tools, tool_definitions
# Pick category by index (1-based) then tool index
cat_idx = 2  # e.g., Information Gathering
tool_idx = 1 # e.g., nmap
all_tools[cat_idx - 1].TOOLS[tool_idx - 1].install()
"

WARNING: Most tool installs will fail on macOS because install() shells out to system package managers (apt, brew). The tool definitions are still useful for discovery — Hermes should suggest the user install the underlying tool directly via Homebrew.

Categories (summary)

| # | Category | Tool Count | |----|----------------------------|-----------:| | 1 | 🛡 Anonymously Hiding | 2 | | 2 | 🔍 Information Gathering | 26 | | 3 | 📚 Wordlist Generator | 7 | | 4 | 📶 Wireless Attack | 13 | | 5 | 🧩 SQL Injection | 7 | | 6 | 🎣 Phishing Attack | 17 | | 7 | 🌐 Web Attack | 20 | | 8 | 🔧 Post Exploitation | 10 | | 9 | 🕵 Forensic | 8 | | 10 | 📦 Payload Creation | 8 | | 11 | 🧰 Exploit Framework | 4 | | 12 | 🔁 Reverse Engineering | 5 | | 13 | ⚡ DDOS Attack | 6 | | 14 | 🖥 Remote Admin (RAT) | 1 | | 15 | 💥 XSS Attack | 9 | | 16 | 🖼 Steganography | 4 | | 17 | 🏢 Active Directory | 6 | | 18 | ☁ Cloud Security | 4 | | 19 | 📱 Mobile Security | 3 | | 20 | ✨ Other Tools | 11 | | 21 | ♻ Update / Uninstall | 2 |

Workflow for Hermes

  1. If user asks "what tools for X?", search or use tags to find matches.
  2. If user asks "list all tools in category Y", programmatically enumerate that category.
  3. If user asks "install tool Z from hackingtool", explain that hackingtool's install wrappers target Linux (apt/brew), but Hermes can install the tool natively on macOS instead. Offer to find and install via Homebrew.
  4. If user asks "run hackingtool", remind them to use the hackingtool command from an interactive terminal (the TUI needs stdin).
  5. If user asks "search hackingtool for KEYWORD", use the programmatic search method above.

Pitfalls

  • Never try hackingtool --help in a non-TTY — it will hang on Prompt.ask.
  • Most install() methods will fail on macOS — accept this gracefully and offer native alternatives.
  • The TUI is Rich-based and requires TERM env var set.
  • ~/.hackingtool/tools/ is where tools WOULD be installed; it's empty by default.
  • Do NOT use sudo with hackingtool — the venv install is user-local.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.