jthack ffuf_claude_skill
COMMUNITYLABSCO SUMMARY
The skill's own description covers what it teaches: authenticated fuzzing with raw HTTP requests, auto-calibration, and result analysis, on top of whatever wordlists a project already has. Installing it means cloning the repository and copying its ffuf-skill folder into ~/.claude/skills by hand — there is no npx skills add or equivalent one-line install path in the README, and ffuf itself has to already be on the system (brew install ffuf or go install github.com/ffuf/ffuf/v2@latest) before the skill can do anything.
What this is for. Directory, file, subdomain, and API-endpoint discovery during authorized penetration testing — the README states outright that unauthorized use is illegal, that testing is limited to systems you own or have explicit permission to test, and that responsible disclosure applies. It is a narrow, single-purpose skill, not a general security toolkit: fuzzing is the one thing it does.
READ THE FULL ANALYSIS
One skill, no maintained package structure around it. There is no versioning, no changelog, and no second skill in the repository — what you see in the README is the entire scope of the project.
WHAT'S INSIDE
1 showing · 1 totalffuf-web-fuzzing
Ready-to-run commands for ffuf, a security-testing tool that hammers a website with wordlists to uncover its hidden pages, subdomains, and URL parameters, with the repetitive noise filtered out automatically.
HOW TO GET IT
npx skills add jthack/ffuf_claude_skillnpx skills add jthack/ffuf_claude_skill --skill <name> --full-depthPick the skill name from the Skills tab — each entry there installs independently.