fullscan
GitHub执行全量安全评估,通过多阶段协调智能体跳过已知耗尽区域并复用上下文。新增最高标准,要求覆盖核心资产、记录正负结果、关联低危漏洞以形成攻击链,并确保最终报告包含确认发现及残留风险分析。
Trigger Scenarios
Install
npx skills add H-mmer/pentest-agents --skill fullscan -g -y
SKILL.md
Frontmatter
{
"name": "fullscan",
"description": "Full security assessment with brain coordination. Multi-phase, skips known-exhausted areas, builds on prior knowledge."
}
ALL agents dispatched by this command MUST use in the subagent dispatch tool call.
Full security assessment on: $ARGUMENTS
Phase 0: Brain Briefing
uv run python3 ../../tools/brain.py init(if first run)uv run python3 ../../tools/brain.py brief $ARGUMENTSuv run python3 ../../tools/scope_check.py $ARGUMENTS
Phase 1: Recon (skip already-discovered assets)
Launch recon agent with brain context. Focus on discovering NEW subdomains and services beyond what's already known.
Phase 2: Scanning (skip exhausted areas)
Launch IN PARALLEL, each with brain context about what's been scanned before:
vuln-scanner— skip known false positives, focus new hostsconfig-auditor— check if previously noted misconfigs are fixedjs-analyzer— focus on new/changed JS files
Record all results to the brain after each agent returns.
Phase 3: Targeted Testing (brain-guided)
Based on Phase 2 + brain knowledge, selectively launch ONLY agents targeting UNTESTED or ACTIVE vectors:
xss-hunterONLY on endpoints not marked exhaustedapi-auditONLY on newly discovered or untested endpointsauth-testerONLY if new auth flows found
Record all results to the brain.
Phase 4: Reporting
uv run python3 ../../tools/dedup_findings.py --scan-dir scans/ --db findings.json --statsuv run python3 ../../tools/brain.py status- Launch
poc-builderfor each confirmed finding - Launch
report-writerwith full brain context uv run python3 ../../tools/brain.py log "Full scan completed on $ARGUMENTS"
Top-Tier Fullscan Standard
A full scan must leave a defensible coverage ledger.
- Start with the crown jewels: auth, tenant data, billing, admin, integrations, uploads, webhooks, exports, AI/tool surfaces, and source/repo exposure.
- For each phase, record both positives and negatives. "Scanned" is invalid unless it names tools, targets, timestamps, and skipped areas.
- Do not let scanner output dominate. Use scanners to find leads, then spend human-grade effort on state changes, authorization boundaries, and parser differentials.
- Before reporting, run
/correlateor/chainon all confirmed and partial findings. Single low bugs should not escape the scan if a plausible chain remains. - Final output must contain: confirmed findings, killed false positives, exhausted high-value paths, untested residual risk, and the next best command.
Version History
- 41d49b6 Current 2026-07-24 11:58


