chain

GitHub

构建深层漏洞利用链,通过分发chain-builder代理递归分析。新增顶级链标准,要求按能力分类初始漏洞并评估路径,确保链路逻辑连贯且符合策略,提升链条质量与安全性。

.claude/skills/chain/SKILL.md H-mmer/pentest-agents

Trigger Scenarios

用户输入 /chain 命令 需要构建从已知漏洞出发的后续利用路径

Install

npx skills add H-mmer/pentest-agents --skill chain -g -y
More Options

Non-standard path

npx skills add https://github.com/H-mmer/pentest-agents/tree/main/.claude/skills/chain -g -y

Use without installing

npx skills use H-mmer/pentest-agents@chain

指定 Agent (Claude Code)

npx skills add H-mmer/pentest-agents --skill chain -a claude-code -g -y

安装 repo 全部 skill

npx skills add H-mmer/pentest-agents --all -g -y

预览 repo 内 skill

npx skills add H-mmer/pentest-agents --list

SKILL.md

Frontmatter
{
    "name": "chain",
    "description": "Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: \/chain (then describe bug A)",
    "disable-model-invocation": false
}

Build exploit chain from: $ARGUMENTS

Process

  1. Read brain for current target context: uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py brief <target>

  2. Get bug A description:

    • If $ARGUMENTS contains a bug description → use it
    • Else if brain has a recent confirmed finding → use that
    • Else → ask user to describe the confirmed bug
  3. Read rules/chain-table.md — the capability→next-bug table

  4. Read policy.md — extract policy preamble for the agent

  5. ALWAYS dispatch chain-builder agent (model: inherit) with:

    • The confirmed bug A description (exact HTTP request/response)
    • The full chain table from rules/chain-table.md
    • Policy preamble (scope + required headers + restrictions)
    • Brain context (tech stack, tested endpoints, known capabilities)
    • Writeup intelligence: call search_writeups "chain <bug class> escalation" if MCP available
  6. After agent returns:

    • If chain found:
      • uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> confirmed "chain: <summary>" "<full chain>"
      • Show chain to user with combined impact and CVSS
      • Suggest: /validate then /report
    • If dead end:
      • uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> exhausted "chain from <bug A>" "<candidates tried>"
      • Show what was tried and why it failed

No inline chain logic. No capability table. The chain-builder agent does all the work.

Top-Tier Chain Standard

A chain is valuable only when each link grants a concrete capability.

Before dispatching, classify bug A as one capability:

  • identity control: login, link, session, token, role, invite
  • data read: PII, secrets, tenant data, internal API response
  • data write: config, webhook, template, profile, billing, integration
  • execution: script, server-side call, command, workflow run, model/tool action
  • network pivot: SSRF, callback, metadata, internal host reachability

Ask the chain-builder for three paths: fastest proof, highest impact, and safest policy-compliant path. Kill chains that require guessing, prohibited data access, or unbounded scanning. A reportable chain must include end-to-end reproduction, where link 2 consumes the capability from link 1 rather than merely coexisting with it.

Version History

  • 41d49b6 Current 2026-07-24 11:56

Same Skill Collection

.claude/skills/analyze/SKILL.md
.claude/skills/autopilot/SKILL.md
.claude/skills/brain/SKILL.md
.claude/skills/correlate/SKILL.md
.claude/skills/dupcheck/SKILL.md
.claude/skills/fullscan/SKILL.md
.claude/skills/hunt/SKILL.md
.claude/skills/learn/SKILL.md
.claude/skills/mindmap/SKILL.md
.claude/skills/monitor/SKILL.md
.claude/skills/new/SKILL.md
.claude/skills/pipeline/SKILL.md
.claude/skills/quality/SKILL.md
.claude/skills/quickscan/SKILL.md
.claude/skills/remember/SKILL.md
.claude/skills/report/SKILL.md
.claude/skills/resume/SKILL.md
.claude/skills/sast/SKILL.md
.claude/skills/status/SKILL.md
.claude/skills/submit/SKILL.md
.claude/skills/surface/SKILL.md
.claude/skills/sync/SKILL.md
.claude/skills/triage/SKILL.md
.claude/skills/validate/SKILL.md
providers/codex/.agents/skills/analyze/SKILL.md
providers/codex/.agents/skills/autopilot/SKILL.md
providers/codex/.agents/skills/brain/SKILL.md
providers/codex/.agents/skills/chain/SKILL.md
providers/codex/.agents/skills/correlate/SKILL.md
providers/codex/.agents/skills/dupcheck/SKILL.md
providers/codex/.agents/skills/fullscan/SKILL.md
providers/codex/.agents/skills/hunt/SKILL.md
providers/codex/.agents/skills/learn/SKILL.md
providers/codex/.agents/skills/mindmap/SKILL.md
providers/codex/.agents/skills/monitor/SKILL.md
providers/codex/.agents/skills/new/SKILL.md
providers/codex/.agents/skills/pipeline/SKILL.md
providers/codex/.agents/skills/quality/SKILL.md
providers/codex/.agents/skills/quickscan/SKILL.md
providers/codex/.agents/skills/remember/SKILL.md
providers/codex/.agents/skills/report/SKILL.md
providers/codex/.agents/skills/resume/SKILL.md
providers/codex/.agents/skills/sast/SKILL.md
providers/codex/.agents/skills/status/SKILL.md
providers/codex/.agents/skills/submit/SKILL.md
providers/codex/.agents/skills/surface/SKILL.md
providers/codex/.agents/skills/sync/SKILL.md
providers/codex/.agents/skills/triage/SKILL.md
providers/codex/.agents/skills/validate/SKILL.md

Metadata

Files
0
Version
41d49b6
Hash
d33cc5c7
Indexed
2026-07-24 11:56

Home - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-06 18:38
浙ICP备14020137号-1 $Map of visitor$