claudeers.
// Claude Skills

paranoid

Your app is guilty until proven secure: an agent skill whose /hack-me breaks into your own running app, proves each bug with a real request, patches it, and…

// Claude Skills[ cli ][ api ][ web ][ claude ]#claude#agent-skills#ai-agents#appsec#claude-code#llm#mcp#penetration-testing#skills◷ MIT$open-sourceupdated 19 days ago
Actively maintained
99/100
last commit 10 days ago
last release none
releases 0
open issues 3

Install with your AI

Paste into Claude Code, Cursor, or any agent — it reads the repo and wires the tool into your project.

Install and set up paranoid (git-clone project) into my current project.
Found on https://claudeers.com/paranoid
Repo: https://github.com/kulchankas/paranoid
Homepage/docs: —
Detected install method: git-clone → git clone https://github.com/kulchankas/paranoid
Category: skills. Platforms: cli, api, web.
Read the repo's README for exact setup and env vars, then install it and wire it into my project.

Claudeers Health Verdict:
active; community-verified: false. Confirm the source before running anything.
// or clone
git clone https://github.com/kulchankas/paranoid

// compatibility

Platformscli, api, web
Operating systems—
AI compatibilityclaude
LicenseMIT
Pricingopen-source
LanguagePython

Get your FREE $2.50 API credits to access TickAtlas financial data ↗

paranoid — an agent skill that pentests your own running app: /hack-me finds, proves, patches and re-verifies real vulnerabilities

🕵️ paranoid

Your app is guilty until proven secure. /hack-me breaks into your own running app, proves each hole with a real request, patches it, and re-verifies — on localhost, with receipts.

paranoid is an agent skill for Claude Code, Codex, and Cursor. Its core is /hack-me — an authorized, localhost-only self-pentest loop that attacks your own app the way an attacker would, then closes what it finds.

find  →  prove  →  patch  →  re-verify

hack-me finds, proves, patches and re-verifies four real vulnerabilities in a running app


Why this isn't another "write secure code" skill

I started with the obvious thing — a skill that tells the agent to write secure code — and then benchmarked it honestly before believing in it. The harness (benchmark/) generates the same tasks with and without the skill and runs real exploits against whatever the model writes.

The result was a clean negative:

ModelTasksExploit rate without skillwith skillEffect
Fable 5.1isolated functions (easy)0%0%none
Opusisolated functions (easy)0%0%none
Opusisolated functions (neutral/tempting)0%0%none

On an isolated function, a capable model already writes the secure version unprompted — ownership in the WHERE clause, parameterized queries, field allow-lists — with no skill at all. Advice adds nothing there. (The harness isn't rigged: it flags deliberately-insecure reference code at 100% and secure code at 0%.)

Real vulnerabilities don't live in one tidy function. They live in the wiring of a whole running app: auth on one route but not the next, a request body that quietly sets is_admin, a search box that concatenates SQL. A model can't hold all of that in its head while coding. So paranoid stops advising and starts attacking the running app.

/hack-me, proven

Against a small but realistic invoicing API (examples/ledgerlite), a hack-me agent that was told nothing about the app's bugs found four by probing, proved each with a live request, patched them, and re-verified:

#Found by probing the APIClassProofAfter patch
1Any user reads any invoiceIDOR / broken object authHTTP 200 with another user's invoice404
2/admin/users open to anyone logged inbroken function authfull user directory dumped403
3/search?email= SQL injectionSQLiplaintext passwords dumped via UNION[]
4/profile accepts is_adminmass assignment → privilege escalationregular user became admin400

Every legitimate request still returns 200 after the fixes. The full walkthrough — exact exploit requests, responses, diffs, and re-verification — is in examples/ledgerlite/HACKME_REPORT.md. Reproduce it: python3 examples/ledgerlite/app.py, then run /hack-me.

That target was written as a demo, so it proves the loop works end-to-end. Point /hack-me at your app for your own results.

Proven on an app we didn't write

The harder claim is code we don't control. Pointed at OWASP VAmPI — a well-known third-party vulnerable API — with nothing but its URL, /hack-me found, proved, patched and re-verified six real bugs, including SQL-injecting the admin's password out through the API and an unauthenticated endpoint dumping every user's plaintext password:

hack-me finds, proves, patches and re-verifies six real vulnerabilities in OWASP VAmPI

#FindingOWASP APIStatus
1Unauth /users/v1/_debug dumps every passwordAPI3/5401/403
2Read any user's private book secret (BOLA)API1404
3Register with admin:true → privilege escalationAPI6admin=false
4Change any user's password (account takeover)API1victim untouched
5SQLi in user lookup (UNION-dumps passwords)API8404
6Debugger + stack traces exposedAPI7clean errors

Notably, VAmPI's own global "secure mode" flag closed only four of the six — the critical password dump stayed open until patched. /hack-me caught it by replaying every exploit instead of trusting the flag. Full receipts: examples/vampi/HACKME_REPORT.md.

What /hack-me actually does

  1. Maps your running app and picks the risk classes it's exposed to.
  2. Probes for each — one crafted request that only succeeds if the bug is real.
  3. Proves every finding with the actual request/response (no theorizing).
  4. Patches the root cause with a minimal, behavior-preserving fix.
  5. Re-verifies by replaying the exact exploit — a finding isn't closed until it fails.

Guardrails, always: your own / authorized targets, localhost only, non-destructive proofs. It won't touch third-party hosts, evade detection, or build live malware. See commands/hack-me.md.

Install

npx skills add kulchankas/paranoid/skills/paranoid

Then copy commands/hack-me.md into your agent's commands dir (e.g. .claude/commands/) so /hack-me is available. No dependencies, no network calls, no telemetry — it's Markdown your agent reads.

python3 my_app.py            # start your app locally
/hack-me                     # point the agent at http://localhost:<port>

Also inside: the paranoid skill (secure-by-default companion)

The guidance the benchmark tested still earns its place as a companion while you code and as hack-me's knowledge base — concrete failure modes and fixes for the vulnerability classes that actually ship in vibe-coded apps:

Load it while building; run /hack-me to check whether it held.

The benchmark

An honest, reproducible harness for the question "does a security skill actually reduce vulnerabilities?" — plus the negative result above and how to re-run it: benchmark/.

Scope & ethics

paranoid secures your code and pentests your running app, with your say-so. It is not built to target third-party systems, scan hosts you don't own, evade detection, or produce live malware, and it will decline to. Authorized, defensive, local.

Roadmap

  • /hack-me loop — find → prove → patch → re-verify, on localhost
  • Reproducible skill-efficacy benchmark + the honest result behind the pivot
  • Independent-app proof — OWASP VAmPI: 6 real bugs found, fixed & re-verified
  • More benchmark task classes — 18 now (IDOR, missing auth, SQLi, mass assignment, path traversal, SSRF, XSS, command injection, open redirect, JWT auth, leaked secrets, CSRF, template injection, XXE, unrestricted upload, permissive CORS, weak password storage)
  • /hack-me framework guides (Next.js, FastAPI, Express)

paranoid is v0.1 and actively developed — issues and PRs welcome.

Contributing

New vulnerability classes, framework guides, and independent-app proofs are the most useful contributions — see CONTRIBUTING.md for the format and the honesty rules, and SECURITY.md for scope. Good first issues are labeled in the tracker.

License

MIT © 2026 kulchankas. See LICENSE.

// faq

What is paranoid?

Your app is guilty until proven secure: an agent skill whose /hack-me breaks into your own running app, proves each bug with a real request, patches it, and re-verifies. Claude Code · Codex · Cursor.. It is open-source on GitHub.

Is paranoid free to use?

paranoid is open-source under the MIT license, so it is free to use.

What category does paranoid belong to?

paranoid is listed under skills in the Claudeers registry of Claude-compatible tools.

3 views
★ 42 stars
unclaimed
updated 19 days ago

// embed badge

paranoid on Claudeers
[![Claudeers](https://claudeers.com/api/badge/paranoid.svg)](https://claudeers.com/paranoid)

// retro hit counter

paranoid hit counter
[![Hits](https://claudeers.com/api/counter/paranoid.svg)](https://claudeers.com/paranoid)

// reviews

// guestbook

0/500

// related in Claude Skills

🔓

An agentic skills framework & software development methodology that works.

// skillsobra/⟨Shell⟩★ 292,190◷ MIT[ claude ]
🔓

Public repository for Agent Skills

// skillsanthropics/⟨Python⟩★ 178,324[ claude ]
🔓

💫 Toolkit to help you get started with Spec-Driven Development

// skillsgithub/⟨Python⟩★ 138,919◷ MIT[ claude ]
🔓

AI coding assistant skill (Claude Code, Codex, OpenCode, Cursor, Gemini CLI, and more). Turn any folder of code, SQL schemas, R scripts, shell scripts, docs,…

// skillsGraphify-Labs/⟨Python⟩★ 123,800◷ MIT[ claude ]
→ see how paranoid connects across the ecosystem