analyze

GitHub

利用AI分析侦察数据,识别高价值目标并推荐攻击策略。通过映射皇冠宝石、排名攻击路径及检测盲区,结合权重评估生成可执行的狩猎建议,辅助红队高效发现漏洞。

.claude/skills/analyze/SKILL.md H-mmer/pentest-agents

Trigger Scenarios

用户请求对目标进行安全分析或策略规划 输入包含 /analyze 命令后跟目标地址

Install

npx skills add H-mmer/pentest-agents --skill analyze -g -y
More Options

Non-standard path

npx skills add https://github.com/H-mmer/pentest-agents/tree/main/.claude/skills/analyze -g -y

Use without installing

npx skills use H-mmer/pentest-agents@analyze

指定 Agent (Claude Code)

npx skills add H-mmer/pentest-agents --skill analyze -a claude-code -g -y

安装 repo 全部 skill

npx skills add H-mmer/pentest-agents --all -g -y

预览 repo 内 skill

npx skills add H-mmer/pentest-agents --list

SKILL.md

Frontmatter
{
    "name": "analyze",
    "description": "Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: \/analyze <target>",
    "disable-model-invocation": false
}

AI-powered analysis of recon data for: $ARGUMENTS

Process

  1. Read all recon data: ls recon/ and read key files
  2. Read brain data: uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py brief $ARGUMENTS
  3. Read tech stack intel: uv run python3 $CLAUDE_PROJECT_DIR/tools/intel_engine.py suggest <detected-stack>
  4. Read hacktivity patterns: uv run python3 $CLAUDE_PROJECT_DIR/tools/intel_engine.py analyze

Analysis Tasks (do all of these)

Crown Jewel Mapping

What's the most valuable thing an attacker could access on this target?

  • Financial data? → hunt IDOR on payment/billing endpoints
  • User PII? → hunt IDOR on profile/export endpoints
  • Admin access? → hunt auth bypass on admin endpoints
  • Infrastructure? → hunt SSRF → cloud metadata

Attack Path Ranking

Given the tech stack and recon output, rank the top 5 attack paths by:

  1. Likelihood of vulnerability existing (based on tech stack patterns)
  2. Impact if exploited (based on endpoint function)
  3. Competition (based on hacktivity — avoid heavily-reported vuln classes)
  4. Your past success (from brain patterns)

Blind Spot Detection

What has NOT been tested? What endpoints have no brain data? Cross-reference recon output against brain tested endpoints. Flag untested high-value endpoints.

Output

ANALYSIS: target.com
═════════════════════

Crown Jewels: [what's most valuable]

Top 5 Attack Paths:
1. [endpoint] × [vuln class] — likelihood: HIGH, impact: CRITICAL
2. ...

Blind Spots (untested P1 surface):
- /api/v2/payments/* — NO DATA in brain
- /api/v2/admin/* — NO DATA in brain

Recommendation: /hunt target.com --vuln-class [best bet]

Top-Tier Operator Addendum

Treat /analyze as a thesis generator, not a summary command. The output must make the next hour of hunting obvious.

  1. Build a weighted table before recommending anything:
    • asset_value: revenue, PII, admin, secrets, infrastructure, tenant boundary
    • exploit_likelihood: stack age, exposed methods, auth complexity, parser surface, prior bug class fit
    • novelty: low hacktivity overlap, new endpoint, changed JS, unusual integration, weak vendor pattern
    • proof_path: exact request needed to prove impact, required accounts, required evidence artifact
    • policy_friction: rate limits, forbidden data access, third-party scope, credential validation rules
  2. Prefer attack paths with a short proof path over impressive theory. A boring IDOR with two accounts and a readback beats a speculative SSRF with no egress signal.
  3. Include negative evidence. If /api/admin/* looks valuable but all routes are 403 with no differential, say that and explain what would change the ranking.
  4. Separate P1 now, P2 if time, and Kill for this session. Top-tier analysis saves time by deleting tempting dead ends.
  5. Every recommendation must name the next command and the exact first test: /hunt target --vuln-class idor plus the endpoint pair, account pair, and field to compare.

Version History

  • 41d49b6 Current 2026-07-24 11:56

Same Skill Collection

.claude/skills/autopilot/SKILL.md
.claude/skills/brain/SKILL.md
.claude/skills/chain/SKILL.md
.claude/skills/correlate/SKILL.md
.claude/skills/dupcheck/SKILL.md
.claude/skills/fullscan/SKILL.md
.claude/skills/hunt/SKILL.md
.claude/skills/learn/SKILL.md
.claude/skills/mindmap/SKILL.md
.claude/skills/monitor/SKILL.md
.claude/skills/new/SKILL.md
.claude/skills/pipeline/SKILL.md
.claude/skills/quality/SKILL.md
.claude/skills/quickscan/SKILL.md
.claude/skills/remember/SKILL.md
.claude/skills/report/SKILL.md
.claude/skills/resume/SKILL.md
.claude/skills/sast/SKILL.md
.claude/skills/status/SKILL.md
.claude/skills/submit/SKILL.md
.claude/skills/surface/SKILL.md
.claude/skills/sync/SKILL.md
.claude/skills/triage/SKILL.md
.claude/skills/validate/SKILL.md
providers/codex/.agents/skills/analyze/SKILL.md
providers/codex/.agents/skills/autopilot/SKILL.md
providers/codex/.agents/skills/brain/SKILL.md
providers/codex/.agents/skills/chain/SKILL.md
providers/codex/.agents/skills/correlate/SKILL.md
providers/codex/.agents/skills/dupcheck/SKILL.md
providers/codex/.agents/skills/fullscan/SKILL.md
providers/codex/.agents/skills/hunt/SKILL.md
providers/codex/.agents/skills/learn/SKILL.md
providers/codex/.agents/skills/mindmap/SKILL.md
providers/codex/.agents/skills/monitor/SKILL.md
providers/codex/.agents/skills/new/SKILL.md
providers/codex/.agents/skills/pipeline/SKILL.md
providers/codex/.agents/skills/quality/SKILL.md
providers/codex/.agents/skills/quickscan/SKILL.md
providers/codex/.agents/skills/remember/SKILL.md
providers/codex/.agents/skills/report/SKILL.md
providers/codex/.agents/skills/resume/SKILL.md
providers/codex/.agents/skills/sast/SKILL.md
providers/codex/.agents/skills/status/SKILL.md
providers/codex/.agents/skills/submit/SKILL.md
providers/codex/.agents/skills/surface/SKILL.md
providers/codex/.agents/skills/sync/SKILL.md
providers/codex/.agents/skills/triage/SKILL.md
providers/codex/.agents/skills/validate/SKILL.md

Metadata

Files
0
Version
41d49b6
Hash
f7691529
Indexed
2026-07-24 11:56

Home - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-06 17:28
浙ICP备14020137号-1 $Map of visitor$