chain
GitHub构建深层漏洞利用链,通过分发chain-builder代理递归分析。新增顶级链标准,要求按能力分类初始漏洞并评估路径,确保链路逻辑连贯且符合策略,提升链条质量与安全性。
Trigger Scenarios
Install
npx skills add H-mmer/pentest-agents --skill chain -g -y
SKILL.md
Frontmatter
{
"name": "chain",
"description": "Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: \/chain (then describe bug A)",
"disable-model-invocation": false
}
Build exploit chain from: $ARGUMENTS
Process
-
Read brain for current target context:
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py brief <target> -
Get bug A description:
- If
$ARGUMENTScontains a bug description → use it - Else if brain has a recent confirmed finding → use that
- Else → ask user to describe the confirmed bug
- If
-
Read
rules/chain-table.md— the capability→next-bug table -
Read
policy.md— extract policy preamble for the agent -
ALWAYS dispatch
chain-builderagent (model: inherit) with:- The confirmed bug A description (exact HTTP request/response)
- The full chain table from
rules/chain-table.md - Policy preamble (scope + required headers + restrictions)
- Brain context (tech stack, tested endpoints, known capabilities)
- Writeup intelligence: call
search_writeups "chain <bug class> escalation"if MCP available
-
After agent returns:
- If chain found:
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> confirmed "chain: <summary>" "<full chain>"- Show chain to user with combined impact and CVSS
- Suggest:
/validatethen/report
- If dead end:
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> exhausted "chain from <bug A>" "<candidates tried>"- Show what was tried and why it failed
- If chain found:
No inline chain logic. No capability table. The chain-builder agent does all the work.
Top-Tier Chain Standard
A chain is valuable only when each link grants a concrete capability.
Before dispatching, classify bug A as one capability:
- identity control: login, link, session, token, role, invite
- data read: PII, secrets, tenant data, internal API response
- data write: config, webhook, template, profile, billing, integration
- execution: script, server-side call, command, workflow run, model/tool action
- network pivot: SSRF, callback, metadata, internal host reachability
Ask the chain-builder for three paths: fastest proof, highest impact, and safest policy-compliant path. Kill chains that require guessing, prohibited data access, or unbounded scanning. A reportable chain must include end-to-end reproduction, where link 2 consumes the capability from link 1 rather than merely coexisting with it.
Version History
- 41d49b6 Current 2026-07-24 11:56


