chain

GitHub

构建深层漏洞利用链。读取上下文与规则,分发chain-builder代理递归探索能力跃迁路径。按身份、数据等分类初始漏洞,生成最快、最高影响及安全合规的三条路径,并记录结果或失败原因。

providers/openclaw/.agents/skills/cmd-chain/SKILL.md H-mmer/pentest-agents

Trigger Scenarios

用户请求构建漏洞利用链 需要递归探索漏洞利用路径

Install

npx skills add H-mmer/pentest-agents --skill chain -g -y
More Options

Non-standard path

npx skills add https://github.com/H-mmer/pentest-agents/tree/main/providers/openclaw/.agents/skills/cmd-chain -g -y

Use without installing

npx skills use H-mmer/pentest-agents@chain

指定 Agent (Claude Code)

npx skills add H-mmer/pentest-agents --skill chain -a claude-code -g -y

安装 repo 全部 skill

npx skills add H-mmer/pentest-agents --all -g -y

预览 repo 内 skill

npx skills add H-mmer/pentest-agents --list

SKILL.md

Frontmatter
{
    "name": "chain",
    "description": "Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: \/chain (then describe bug A)"
}

Build exploit chain from: $ARGUMENTS

Process

  1. Read brain for current target context: uv run python3 ../../tools/brain.py brief <target>

  2. Get bug A description:

    • If $ARGUMENTS contains a bug description → use it
    • Else if brain has a recent confirmed finding → use that
    • Else → ask user to describe the confirmed bug
  3. Read rules/chain-table.md — the capability→next-bug table

  4. Read policy.md — extract policy preamble for the agent

  5. ALWAYS dispatch chain-builder agent (model: inherit) with:

    • The confirmed bug A description (exact HTTP request/response)
    • The full chain table from rules/chain-table.md
    • Policy preamble (scope + required headers + restrictions)
    • Brain context (tech stack, tested endpoints, known capabilities)
    • Writeup intelligence: call search_writeups "chain <bug class> escalation" if MCP available
  6. After agent returns:

    • If chain found:
      • uv run python3 ../../tools/brain.py record <target> confirmed "chain: <summary>" "<full chain>"
      • Show chain to user with combined impact and CVSS
      • Suggest: /validate then /report
    • If dead end:
      • uv run python3 ../../tools/brain.py record <target> exhausted "chain from <bug A>" "<candidates tried>"
      • Show what was tried and why it failed

No inline chain logic. No capability table. The chain-builder agent does all the work.

Top-Tier Chain Standard

A chain is valuable only when each link grants a concrete capability.

Before dispatching, classify bug A as one capability:

  • identity control: login, link, session, token, role, invite
  • data read: PII, secrets, tenant data, internal API response
  • data write: config, webhook, template, profile, billing, integration
  • execution: script, server-side call, command, workflow run, model/tool action
  • network pivot: SSRF, callback, metadata, internal host reachability

Ask the chain-builder for three paths: fastest proof, highest impact, and safest policy-compliant path. Kill chains that require guessing, prohibited data access, or unbounded scanning. A reportable chain must include end-to-end reproduction, where link 2 consumes the capability from link 1 rather than merely coexisting with it.

Version History

  • 41d49b6 Current 2026-07-24 12:05

Same Skill Collection

.claude/skills/analyze/SKILL.md
.claude/skills/autopilot/SKILL.md
.claude/skills/brain/SKILL.md
.claude/skills/chain/SKILL.md
.claude/skills/correlate/SKILL.md
.claude/skills/dupcheck/SKILL.md
.claude/skills/fullscan/SKILL.md
.claude/skills/hunt/SKILL.md
.claude/skills/learn/SKILL.md
.claude/skills/mindmap/SKILL.md
.claude/skills/monitor/SKILL.md
.claude/skills/new/SKILL.md
.claude/skills/pipeline/SKILL.md
.claude/skills/quality/SKILL.md
.claude/skills/quickscan/SKILL.md
.claude/skills/remember/SKILL.md
.claude/skills/report/SKILL.md
.claude/skills/resume/SKILL.md
.claude/skills/sast/SKILL.md
.claude/skills/status/SKILL.md
.claude/skills/submit/SKILL.md
.claude/skills/surface/SKILL.md
.claude/skills/sync/SKILL.md
.claude/skills/triage/SKILL.md
.claude/skills/validate/SKILL.md
providers/codex/.agents/skills/analyze/SKILL.md
providers/codex/.agents/skills/autopilot/SKILL.md
providers/codex/.agents/skills/brain/SKILL.md
providers/codex/.agents/skills/chain/SKILL.md
providers/codex/.agents/skills/correlate/SKILL.md
providers/codex/.agents/skills/dupcheck/SKILL.md
providers/codex/.agents/skills/fullscan/SKILL.md
providers/codex/.agents/skills/hunt/SKILL.md
providers/codex/.agents/skills/learn/SKILL.md
providers/codex/.agents/skills/mindmap/SKILL.md
providers/codex/.agents/skills/monitor/SKILL.md
providers/codex/.agents/skills/new/SKILL.md
providers/codex/.agents/skills/pipeline/SKILL.md
providers/codex/.agents/skills/quality/SKILL.md
providers/codex/.agents/skills/quickscan/SKILL.md
providers/codex/.agents/skills/remember/SKILL.md
providers/codex/.agents/skills/report/SKILL.md
providers/codex/.agents/skills/resume/SKILL.md
providers/codex/.agents/skills/sast/SKILL.md
providers/codex/.agents/skills/status/SKILL.md
providers/codex/.agents/skills/submit/SKILL.md
providers/codex/.agents/skills/surface/SKILL.md
providers/codex/.agents/skills/sync/SKILL.md
providers/codex/.agents/skills/triage/SKILL.md
providers/codex/.agents/skills/validate/SKILL.md

Metadata

Files
0
Version
41d49b6
Hash
b763a09b
Indexed
2026-07-24 12:05

Accueil - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-08 19:20
浙ICP备14020137号-1 $Carte des visiteurs$