Agent Skills
› H-mmer/pentest-agents
› sync
sync
GitHub从漏洞众测平台同步程序范围、策略和黑客活动数据。解析平台和程序句柄,调用MCP工具获取数据并写入本地文件。初始化知识库后,提取关键情报(如常见漏洞类型、重复项)并更新大脑。最终总结范围、政策亮点及活动模式,提供狩猎倾向建议。
Trigger Scenarios
用户请求同步特定平台的漏洞赏金计划数据
输入格式为 /sync <platform> <program_handle>
Install
npx skills add H-mmer/pentest-agents --skill sync -g -y
SKILL.md
Frontmatter
{
"name": "sync",
"description": "Sync program scope, policy, and hacktivity from a bug bounty platform. Usage: \/sync hackerone tesla or \/sync bugcrowd uber"
}
Sync bug bounty program data: $ARGUMENTS
Parse the arguments as:
- Use the
bounty-platformsMCP server toolsync_programwith the platform and program handle. This fetches scope, policy, and hacktivity and writes them to the current directory. - After sync completes, run
uv run python3 ../../tools/brain.py initif brain isn't initialized yet. - Read the generated
scope.yamlandhacktivity.mdfiles. - Update the brain with key intelligence from hacktivity:
- Run
uv run python3 ../../tools/brain.py log "Synced program data from <platform>/<program>" - If hacktivity shows common vulnerability types, note them as priority areas
- If hacktivity shows many duplicates of a type, note them as areas to avoid
- Run
- Summarize: scope overview, policy highlights (restrictions, safe harbor), and hacktivity patterns (most common vuln types, average bounties).
Top-Tier Sync Standard
Policy is hunting input, not paperwork.
Extract and persist:
- exact in-scope assets, wildcard rules, mobile/API/cloud qualifiers, and third-party exclusions
- required headers, user-agent, testing accounts, sandbox rules, rate limits, and forbidden actions
- severity exclusions and never-pay classes
- payout hints from hacktivity: accepted classes, duplicate-heavy classes, bounty tiers, triage language
- newly added or removed assets since last sync
End with a hunt bias: where the program appears to pay, where it appears saturated, and what proof standard the policy implies.
Version History
- 41d49b6 Current 2026-07-24 12:06


