agentsclimarketplace

Python exploit runtime

Skill xAmirHamza77/PenKit51/skills/python-exploit-runtime

PenKit51 — Open-source AI penetration testing platform with 63 deep exploitation skills, multi-agent orchestration, PoC-validated findings, and native assistant skills for Claude, ChatGPT, and Grok. Authorized testing only.

Install
npx -y skills add xAmirHamza77/PenKit51 --skill python-exploit-runtime

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
  • 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Run Python through exec_command in the SDK sandbox. Use the image-baked caido_api module for Caido proxy automation from Python scripts.

SKILL.md

8.1 KB, ~2.0k tokens by cl100k_base, as published. Nobody here has run it

Python Exploit Runtime

penkit51 AI — professional penetration testing skill pack. Authorized testing only.

Deep Exploitation Guide

Python In The Sandbox

Use exec_command for Python. Use the platform shell executor for Python.

Prefer writing reusable scripts to /workspace/scratch/<name>.py and running them with python3 /workspace/scratch/<name>.py. For short one-off transformations, python3 -c or a small here-document is fine.

The shell parameter on exec_command is for swapping POSIX shells (bash/zsh/sh), not for picking interpreters. Put the interpreter invocation in cmd instead: cmd="python3 -c '...'", not shell=python3, cmd="...". The shell=<interpreter> shortcut breaks in subtle ways — python3 works only with login=False (because the SDK adds -l/-i), and other interpreters (node, ruby, perl) take -e not -c so they fail even with login=False.

Proxy Automation From Python

The sandbox image includes an installed caido_api module. Import it explicitly when Python code needs Caido traffic or replay access:

from caido_api import (
    list_requests,
    list_sitemap,
    repeat_request,
    scope_rules,
    view_request,
    view_sitemap_entry,
)

All helpers are async. Use them inside asyncio.run(...) or an async function:

import asyncio

from caido_api import list_requests, view_request


async def main():
    posts = await list_requests(
        httpql_filter='req.method.eq:"POST" AND req.path.cont:"/api/"',
        first=50,
    )
    candidates = []
    for edge in posts.edges:
        request_id = edge.node.request.id
        body = await view_request(request_id, part="request")
        raw = body.request.raw.decode("utf-8", errors="replace")
        if "id=" in raw or "user=" in raw:
            candidates.append(request_id)

    print(f"{len(candidates)} candidates")
    print(candidates[:10])


asyncio.run(main())

Available helpers:

  • list_requests(httpql_filter=, first=50, after=, sort_by=, sort_order=, scope_id=) returns a cursor-paginated Caido SDK Connection.
  • view_request(request_id, part="request") returns a Caido SDK request object with raw request/response bytes.
  • repeat_request(request_id, modifications={...}) replays a captured request after modifying url, params, headers, body, or cookies.
  • list_sitemap(scope_id=, parent_id=, depth="DIRECT", page=1) walks Caido's request-tree view of the discovered surface. Omit parent_id for root domains; pass an entry id with depth="DIRECT" or "ALL" to drill in.
  • view_sitemap_entry(entry_id) returns one entry plus its 30 most recent related requests.
  • scope_rules(action, allowlist=, denylist=, scope_id=, scope_name=) manages Caido scopes.

For one-off arbitrary requests (e.g. probing a fresh endpoint, hitting an external API), use exec_command with curl / httpx / requests. The sandbox's HTTP_PROXY env routes all such traffic through Caido automatically, so it shows up in list_requests and you can use repeat_request to replay-and-modify any of it.

Workflow

For iterative exploit work, put code in a file:

1. Create or edit `/workspace/scratch/exploit.py` with `apply_patch`.
2. Run it with `exec_command`: `python3 /workspace/scratch/exploit.py`.
3. Edit and rerun until the proof-of-concept is reliable.

Installing extra packages

The sandbox's Python lives in /app/.venv. To add a one-off dependency for an exploit script, use uv (already in the image and much faster than pip):

uv pip install --python /app/.venv/bin/python <package>

Platform Methodology

Python Exploit Runtime

penkit51 AI — professional penetration testing skill pack. Authorized testing only.

Deep Exploitation Guide

Python In The Sandbox

Use exec_command for Python. Use the platform shell executor for Python.

Prefer writing reusable scripts to /workspace/scratch/<name>.py and running them with python3 /workspace/scratch/<name>.py. For short one-off transformations, python3 -c or a small here-document is fine.

The shell parameter on exec_command is for swapping POSIX shells (bash/zsh/sh), not for picking interpreters. Put the interpreter invocation in cmd instead: cmd="python3 -c '...'", not shell=python3, cmd="...". The shell=<interpreter> shortcut breaks in subtle ways — python3 works only with login=False (because the SDK adds -l/-i), and other interpreters (node, ruby, perl) take -e not -c so they fail even with login=False.

Proxy Automation From Python

The sandbox image includes an installed caido_api module. Import it explicitly when Python code needs Caido traffic or replay access:

from caido_api import (
    list_requests,
    list_sitemap,
    repeat_request,
    scope_rules,
    view_request,
    view_sitemap_entry,
)

All helpers are async. Use them inside asyncio.run(...) or an async function:

import asyncio

from caido_api import list_requests, view_request


async def main():
    posts = await list_requests(
        httpql_filter='req.method.eq:"POST" AND req.path.cont:"/api/"',
        first=50,
    )
    candidates = []
    for edge in posts.edges:
        request_id = edge.node.request.id
        body = await view_request(request_id, part="request")
        raw = body.request.raw.decode("utf-8", errors="replace")
        if "id=" in raw or "user=" in raw:
            candidates.append(request_id)

    print(f"{len(candidates)} candidates")
    print(candidates[:10])


asyncio.run(main())

Available helpers:

  • list_requests(httpql_filter=, first=50, after=, sort_by=, sort_order=, scope_id=) returns a cursor-paginated Caido SDK Connection.
  • view_request(request_id, part="request") returns a Caido SDK request object with raw request/response bytes.
  • repeat_request(request_id, modifications={...}) replays a captured request after modifying url, params, headers, body, or cookies.
  • list_sitemap(scope_id=, parent_id=, depth="DIRECT", page=1) walks Caido's request-tree view of the discovered surface. Omit parent_id for root domains; pass an entry id with depth="DIRECT" or "ALL" to drill in.
  • view_sitemap_entry(entry_id) returns one entry plus its 30 most recent related requests.
  • scope_rules(action, allowlist=, denylist=, scope_id=, scope_name=) manages Caido scopes.

For one-off arbitrary requests (e.g. probing a fresh endpoint, hitting an external API), use exec_command with curl / httpx / requests. The sandbox's HTTP_PROXY env routes all such traffic through Caido automatically, so it shows up in list_requests and you can use repeat_request to replay-and-modify any of it.

Workflow

For iterative exploit work, put code in a file:

1. Create or edit `/workspace/scratch/exploit.py` with `apply_patch`.
2. Run it with `exec_command`: `python3 /workspace/scratch/exploit.py`.
3. Edit and rerun until the proof-of-concept is reliable.

Installing extra packages

The sandbox's Python lives in /app/.venv. To add a one-off dependency for an exploit script, use uv (already in the image and much faster than pip):

uv pip install --python /app/.venv/bin/python <package>

Validation & Reporting

  • Confirm every finding with reproducible PoC before reporting
  • Document: severity (CVSS), affected asset, steps, evidence, remediation
  • Use record_vulnerability when running inside the penkit51 platform
  • Chain low-severity findings into higher-impact attack paths
  • Never report without evidence — distinguish hypothesis from confirmed vuln

Validation & Reporting

  • Confirm every finding with reproducible PoC before reporting
  • Document: severity (CVSS), affected asset, steps, evidence, remediation
  • Use record_vulnerability when running inside the penkit51 platform
  • Chain low-severity findings into higher-impact attack paths
  • Never report without evidence — distinguish hypothesis from confirmed vuln

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 326,970. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.