chain

GitHub

构建深层漏洞利用链。通过调用chain-builder代理,结合目标上下文、能力表和策略,递归分析漏洞A的利用路径。支持评估最快、最高影响及安全合规路径,记录结果并建议验证与报告流程。

providers/codex/.agents/skills/chain/SKILL.md H-mmer/pentest-agents

Trigger Scenarios

用户描述一个已知漏洞并希望扩展利用链 系统检测到近期确认的发现需进一步挖掘

Install

npx skills add H-mmer/pentest-agents --skill chain -g -y
More Options

Non-standard path

npx skills add https://github.com/H-mmer/pentest-agents/tree/main/providers/codex/.agents/skills/chain -g -y

Use without installing

npx skills use H-mmer/pentest-agents@chain

指定 Agent (Claude Code)

npx skills add H-mmer/pentest-agents --skill chain -a claude-code -g -y

安装 repo 全部 skill

npx skills add H-mmer/pentest-agents --all -g -y

预览 repo 内 skill

npx skills add H-mmer/pentest-agents --list

SKILL.md

Frontmatter
{
    "name": "chain",
    "description": "Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: \/chain (then describe bug A)"
}

Build exploit chain from: $ARGUMENTS

Process

  1. Read brain for current target context: uv run python3 ../../tools/brain.py brief <target>

  2. Get bug A description:

    • If $ARGUMENTS contains a bug description → use it
    • Else if brain has a recent confirmed finding → use that
    • Else → ask user to describe the confirmed bug
  3. Read rules/chain-table.md — the capability→next-bug table

  4. Read policy.md — extract policy preamble for the agent

  5. ALWAYS dispatch chain-builder agent (model: inherit) with:

    • The confirmed bug A description (exact HTTP request/response)
    • The full chain table from rules/chain-table.md
    • Policy preamble (scope + required headers + restrictions)
    • Brain context (tech stack, tested endpoints, known capabilities)
    • Writeup intelligence: call search_writeups "chain <bug class> escalation" if MCP available
  6. After agent returns:

    • If chain found:
      • uv run python3 ../../tools/brain.py record <target> confirmed "chain: <summary>" "<full chain>"
      • Show chain to user with combined impact and CVSS
      • Suggest: /validate then /report
    • If dead end:
      • uv run python3 ../../tools/brain.py record <target> exhausted "chain from <bug A>" "<candidates tried>"
      • Show what was tried and why it failed

No inline chain logic. No capability table. The chain-builder agent does all the work.

Top-Tier Chain Standard

A chain is valuable only when each link grants a concrete capability.

Before dispatching, classify bug A as one capability:

  • identity control: login, link, session, token, role, invite
  • data read: PII, secrets, tenant data, internal API response
  • data write: config, webhook, template, profile, billing, integration
  • execution: script, server-side call, command, workflow run, model/tool action
  • network pivot: SSRF, callback, metadata, internal host reachability

Ask the chain-builder for three paths: fastest proof, highest impact, and safest policy-compliant path. Kill chains that require guessing, prohibited data access, or unbounded scanning. A reportable chain must include end-to-end reproduction, where link 2 consumes the capability from link 1 rather than merely coexisting with it.

Version History

  • 41d49b6 Current 2026-07-24 11:58

Same Skill Collection

.claude/skills/analyze/SKILL.md
.claude/skills/autopilot/SKILL.md
.claude/skills/brain/SKILL.md
.claude/skills/chain/SKILL.md
.claude/skills/correlate/SKILL.md
.claude/skills/dupcheck/SKILL.md
.claude/skills/fullscan/SKILL.md
.claude/skills/hunt/SKILL.md
.claude/skills/learn/SKILL.md
.claude/skills/mindmap/SKILL.md
.claude/skills/monitor/SKILL.md
.claude/skills/new/SKILL.md
.claude/skills/pipeline/SKILL.md
.claude/skills/quality/SKILL.md
.claude/skills/quickscan/SKILL.md
.claude/skills/remember/SKILL.md
.claude/skills/report/SKILL.md
.claude/skills/resume/SKILL.md
.claude/skills/sast/SKILL.md
.claude/skills/status/SKILL.md
.claude/skills/submit/SKILL.md
.claude/skills/surface/SKILL.md
.claude/skills/sync/SKILL.md
.claude/skills/triage/SKILL.md
.claude/skills/validate/SKILL.md
providers/codex/.agents/skills/analyze/SKILL.md
providers/codex/.agents/skills/autopilot/SKILL.md
providers/codex/.agents/skills/brain/SKILL.md
providers/codex/.agents/skills/correlate/SKILL.md
providers/codex/.agents/skills/dupcheck/SKILL.md
providers/codex/.agents/skills/fullscan/SKILL.md
providers/codex/.agents/skills/hunt/SKILL.md
providers/codex/.agents/skills/learn/SKILL.md
providers/codex/.agents/skills/mindmap/SKILL.md
providers/codex/.agents/skills/monitor/SKILL.md
providers/codex/.agents/skills/new/SKILL.md
providers/codex/.agents/skills/pipeline/SKILL.md
providers/codex/.agents/skills/quality/SKILL.md
providers/codex/.agents/skills/quickscan/SKILL.md
providers/codex/.agents/skills/remember/SKILL.md
providers/codex/.agents/skills/report/SKILL.md
providers/codex/.agents/skills/resume/SKILL.md
providers/codex/.agents/skills/sast/SKILL.md
providers/codex/.agents/skills/status/SKILL.md
providers/codex/.agents/skills/submit/SKILL.md
providers/codex/.agents/skills/surface/SKILL.md
providers/codex/.agents/skills/sync/SKILL.md
providers/codex/.agents/skills/triage/SKILL.md
providers/codex/.agents/skills/validate/SKILL.md

Metadata

Files
0
Version
41d49b6
Hash
94b12cb9
Indexed
2026-07-24 11:58

Home - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-06 21:36
浙ICP备14020137号-1 $Map of visitor$