fullscan
GitHub执行带脑协调的全量安全评估。通过多阶段(侦察、扫描、定向测试)利用共享上下文跳过已知区域,聚焦新资产与未测试向量,最终生成包含POC和详细覆盖记录的防御性报告。
Trigger Scenarios
Install
npx skills add H-mmer/pentest-agents --skill fullscan -g -y
SKILL.md
Frontmatter
{
"name": "fullscan",
"description": "Full security assessment with brain coordination. Multi-phase, skips known-exhausted areas, builds on prior knowledge.",
"disable-model-invocation": false
}
ALL agents dispatched by this command MUST use model: "inherit" in the Agent tool call.
Full security assessment on: $ARGUMENTS
Phase 0: Brain Briefing
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py init(if first run)uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py brief $ARGUMENTSuv run python3 $CLAUDE_PROJECT_DIR/tools/scope_check.py $ARGUMENTS
Phase 1: Recon (skip already-discovered assets)
Launch recon agent with brain context. Focus on discovering NEW subdomains and services beyond what's already known.
Phase 2: Scanning (skip exhausted areas)
Launch IN PARALLEL, each with brain context about what's been scanned before:
vuln-scanner— skip known false positives, focus new hostsconfig-auditor— check if previously noted misconfigs are fixedjs-analyzer— focus on new/changed JS files
Record all results to the brain after each agent returns.
Phase 3: Targeted Testing (brain-guided)
Based on Phase 2 + brain knowledge, selectively launch ONLY agents targeting UNTESTED or ACTIVE vectors:
xss-hunterONLY on endpoints not marked exhaustedapi-auditONLY on newly discovered or untested endpointsauth-testerONLY if new auth flows found
Record all results to the brain.
Phase 4: Reporting
uv run python3 $CLAUDE_PROJECT_DIR/tools/dedup_findings.py --scan-dir scans/ --db findings.json --statsuv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py status- Launch
poc-builderfor each confirmed finding - Launch
report-writerwith full brain context uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py log "Full scan completed on $ARGUMENTS"
Top-Tier Fullscan Standard
A full scan must leave a defensible coverage ledger.
- Start with the crown jewels: auth, tenant data, billing, admin, integrations, uploads, webhooks, exports, AI/tool surfaces, and source/repo exposure.
- For each phase, record both positives and negatives. "Scanned" is invalid unless it names tools, targets, timestamps, and skipped areas.
- Do not let scanner output dominate. Use scanners to find leads, then spend human-grade effort on state changes, authorization boundaries, and parser differentials.
- Before reporting, run
/correlateor/chainon all confirmed and partial findings. Single low bugs should not escape the scan if a plausible chain remains. - Final output must contain: confirmed findings, killed false positives, exhausted high-value paths, untested residual risk, and the next best command.
Version History
- 41d49b6 Current 2026-07-24 11:57


