Agent Skills
› H-mmer/pentest-agents
› brain
brain
GitHub管理渗透测试记忆库,支持初始化、简报、状态查看及记录漏洞证据。强制要求高质量记录规范,包含目标、技术、状态等字段,确保复用性并避免无效存储。
Trigger Scenarios
用户需要初始化或管理脑中的上下文信息
用户希望查看当前测试状态或已知死胡同
用户准备记录新的漏洞发现或测试结果
Install
npx skills add H-mmer/pentest-agents --skill brain -g -y
SKILL.md
Frontmatter
{
"name": "brain",
"description": "Manage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends.",
"disable-model-invocation": false
}
Brain management: $ARGUMENTS
Route to the brain tool:
- If "$ARGUMENTS" is "init": run
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py init - If "$ARGUMENTS" starts with "brief": run
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py brief <target> - If "$ARGUMENTS" is "status": run
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py status - If "$ARGUMENTS" starts with "exhausted": run
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py exhausted <target> - If "$ARGUMENTS" starts with "record": run
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> <status> <technique> "<details>"
After running, also launch the brain agent to update the MEMORY.md index if any state changed.
Top-Tier Memory Bar
Bad memory makes the whole suite worse. Record facts as reusable evidence, not diary entries.
For every record, include:
target: canonical host or repo namesurface: endpoint, file, workflow, account role, or componenttechnique: vuln class plus variant, not just "tested auth"status: confirmed, partial, exhausted, blocked, duplicate-risk, chain-pendingevidence: request id, file path, response marker, screenshot path, command output, or blockernext_action: the exact command or test a future session should run
Never store "no bug" without the tested matrix. An exhausted entry must say what was tried and why that evidence is strong enough to skip it later.
Version History
- 41d49b6 Current 2026-07-24 11:56


