Agent Skills
› H-mmer/pentest-agents
› resume
resume
GitHub恢复安全狩猎任务,展示历史、未测试端点及建议。优先处理链式待办和已验证发现,提供基于脑库的模式匹配建议与行动选项,按价值而非时间排序。
Trigger Scenarios
用户输入 /resume 命令
需要继续之前的安全测试会话
Install
npx skills add H-mmer/pentest-agents --skill resume -g -y
SKILL.md
Frontmatter
{
"name": "resume",
"description": "Resume a previous hunt. Shows hunt history, untested endpoints, memory-informed suggestions. Usage: \/resume target.com",
"disable-model-invocation": false
}
Resume hunt on: $ARGUMENTS
What This Does
- Read brain for target:
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py brief $ARGUMENTS - Read brain exhausted:
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py exhausted $ARGUMENTS - Read chain-pending advisory:
cat .claude/agent-memory-local/chain-pending.md 2>/dev/null— feeder findings from prior session waiting for chain dispatch. SURFACE THESE FIRST — they have proven dollar value if chained, vs untested surface which is speculative. - Generate / refresh chain plan:
uv run python3 $CLAUDE_PROJECT_DIR/tools/chain_plan.py $ARGUMENTS— writesevidence/<target>/CHAIN_PLAN.mdwith 3-5 candidate next-links per pending feeder finding plus the agent to dispatch for each. Read this BEFORE picking the next vuln class — proven feeders trump speculative untested surface. - Read recon data from recon/ directory
- Show what's been tested vs what remains
- Suggest next techniques based on brain patterns
Output
RESUME: target.com
═══════════════════
Brain Status:
Confirmed findings: N
Exhausted techniques: N
Effective techniques: N
Untested Surface:
1. /api/v2/users/{id}/export — not tested
2. /api/v2/users/{id}/share — not tested
...
Suggestions:
- Tech stack [X] matches pattern where IDOR was found before
- Sibling endpoints of confirmed finding not yet tested
Actions:
[h] /hunt target.com — resume hunting
[s] /surface target.com — re-rank attack surface
[r] /recon target.com — re-run recon (surface may have changed)
[m] /monitor check — check for target changes since last session
Top-Tier Resume Logic
Resume by value, not chronology.
Priority order:
chain-pendingconfirmed feeders with clear next link- validated partials needing one proof artifact
- changed assets from
/monitor - untested P1 crown-jewel endpoints
- high-confidence class hypotheses from prior wins
- stale recon refresh
Show what not to redo. If an area is exhausted, include the exact blocker and matrix coverage. A resumed hunt should start with a single best command, not a menu of every possible command.
Version History
- 41d49b6 Current 2026-07-24 11:57


