sync

GitHub

从漏洞众测平台同步程序范围、策略和黑客活动数据。解析平台和程序句柄,调用MCP工具获取数据并写入本地文件。初始化知识库后,提取关键情报(如常见漏洞类型、重复项)并更新大脑。最终总结范围、政策亮点及活动模式,提供狩猎倾向建议。

providers/openclaw/.agents/skills/cmd-sync/SKILL.md H-mmer/pentest-agents

Trigger Scenarios

用户请求同步特定平台的漏洞赏金计划数据 输入格式为 /sync <platform> <program_handle>

Install

npx skills add H-mmer/pentest-agents --skill sync -g -y
More Options

Non-standard path

npx skills add https://github.com/H-mmer/pentest-agents/tree/main/providers/openclaw/.agents/skills/cmd-sync -g -y

Use without installing

npx skills use H-mmer/pentest-agents@sync

指定 Agent (Claude Code)

npx skills add H-mmer/pentest-agents --skill sync -a claude-code -g -y

安装 repo 全部 skill

npx skills add H-mmer/pentest-agents --all -g -y

预览 repo 内 skill

npx skills add H-mmer/pentest-agents --list

SKILL.md

Frontmatter
{
    "name": "sync",
    "description": "Sync program scope, policy, and hacktivity from a bug bounty platform. Usage: \/sync hackerone tesla or \/sync bugcrowd uber"
}

Sync bug bounty program data: $ARGUMENTS

Parse the arguments as: <program_handle>

  1. Use the bounty-platforms MCP server tool sync_program with the platform and program handle. This fetches scope, policy, and hacktivity and writes them to the current directory.
  2. After sync completes, run uv run python3 ../../tools/brain.py init if brain isn't initialized yet.
  3. Read the generated scope.yaml and hacktivity.md files.
  4. Update the brain with key intelligence from hacktivity:
    • Run uv run python3 ../../tools/brain.py log "Synced program data from <platform>/<program>"
    • If hacktivity shows common vulnerability types, note them as priority areas
    • If hacktivity shows many duplicates of a type, note them as areas to avoid
  5. Summarize: scope overview, policy highlights (restrictions, safe harbor), and hacktivity patterns (most common vuln types, average bounties).

Top-Tier Sync Standard

Policy is hunting input, not paperwork.

Extract and persist:

  • exact in-scope assets, wildcard rules, mobile/API/cloud qualifiers, and third-party exclusions
  • required headers, user-agent, testing accounts, sandbox rules, rate limits, and forbidden actions
  • severity exclusions and never-pay classes
  • payout hints from hacktivity: accepted classes, duplicate-heavy classes, bounty tiers, triage language
  • newly added or removed assets since last sync

End with a hunt bias: where the program appears to pay, where it appears saturated, and what proof standard the policy implies.

Version History

  • 41d49b6 Current 2026-07-24 12:06

Same Skill Collection

.claude/skills/analyze/SKILL.md
.claude/skills/autopilot/SKILL.md
.claude/skills/brain/SKILL.md
.claude/skills/chain/SKILL.md
.claude/skills/correlate/SKILL.md
.claude/skills/dupcheck/SKILL.md
.claude/skills/fullscan/SKILL.md
.claude/skills/hunt/SKILL.md
.claude/skills/learn/SKILL.md
.claude/skills/mindmap/SKILL.md
.claude/skills/monitor/SKILL.md
.claude/skills/new/SKILL.md
.claude/skills/pipeline/SKILL.md
.claude/skills/quality/SKILL.md
.claude/skills/quickscan/SKILL.md
.claude/skills/remember/SKILL.md
.claude/skills/report/SKILL.md
.claude/skills/resume/SKILL.md
.claude/skills/sast/SKILL.md
.claude/skills/status/SKILL.md
.claude/skills/submit/SKILL.md
.claude/skills/surface/SKILL.md
.claude/skills/sync/SKILL.md
.claude/skills/triage/SKILL.md
.claude/skills/validate/SKILL.md
providers/codex/.agents/skills/analyze/SKILL.md
providers/codex/.agents/skills/autopilot/SKILL.md
providers/codex/.agents/skills/brain/SKILL.md
providers/codex/.agents/skills/chain/SKILL.md
providers/codex/.agents/skills/correlate/SKILL.md
providers/codex/.agents/skills/dupcheck/SKILL.md
providers/codex/.agents/skills/fullscan/SKILL.md
providers/codex/.agents/skills/hunt/SKILL.md
providers/codex/.agents/skills/learn/SKILL.md
providers/codex/.agents/skills/mindmap/SKILL.md
providers/codex/.agents/skills/monitor/SKILL.md
providers/codex/.agents/skills/new/SKILL.md
providers/codex/.agents/skills/pipeline/SKILL.md
providers/codex/.agents/skills/quality/SKILL.md
providers/codex/.agents/skills/quickscan/SKILL.md
providers/codex/.agents/skills/remember/SKILL.md
providers/codex/.agents/skills/report/SKILL.md
providers/codex/.agents/skills/resume/SKILL.md
providers/codex/.agents/skills/sast/SKILL.md
providers/codex/.agents/skills/status/SKILL.md
providers/codex/.agents/skills/submit/SKILL.md
providers/codex/.agents/skills/surface/SKILL.md
providers/codex/.agents/skills/sync/SKILL.md
providers/codex/.agents/skills/triage/SKILL.md
providers/codex/.agents/skills/validate/SKILL.md

Metadata

Files
0
Version
41d49b6
Hash
1db3c5fa
Indexed
2026-07-24 12:06

Accueil - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-09 05:43
浙ICP备14020137号-1 $Carte des visiteurs$