Agent Skills
› H-mmer/pentest-agents
› learn
learn
GitHub记录平台漏洞报告反馈并更新学习库。解析参数,通过脚本记录响应、更新本地与全局大脑,并展示洞察。核心在于将各类反馈(接受、重复等)转化为未来狩猎规则,生成具体的策略或规则更新。
Trigger Scenarios
需要记录漏洞平台对报告的反馈时
希望根据历史反馈优化后续挖掘策略时
Install
npx skills add H-mmer/pentest-agents --skill learn -g -y
SKILL.md
Frontmatter
{
"name": "learn",
"description": "Record a platform response and update learning. Usage: \/learn <report_id> <status> [--bounty 500] [--vuln-type XSS]",
"disable-model-invocation": false
}
Record platform response: $ARGUMENTS
- Parse arguments and run:
uv run python3 $CLAUDE_PROJECT_DIR/tools/response_tracker.py log $ARGUMENTS - Also update brain:
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py log "Report response: $ARGUMENTS" - Sync to global brain:
uv run python3 $CLAUDE_PROJECT_DIR/tools/global_brain.py sync-from-local - Show updated insights:
uv run python3 $CLAUDE_PROJECT_DIR/tools/response_tracker.py insights
Top-Tier Learning Loop
Convert every platform response into a future hunting rule.
- If accepted: record the decisive proof artifact, impact framing, asset type, vuln variant, bounty tier, and why triage agreed.
- If duplicate: record the duplicated primitive and which uniqueness signal was missing.
- If N/A: record the exact sentence or policy clause that killed it.
- If informative: record the missing chain or business impact required to make it payable.
- If severity changed: record the evidence that moved it up or down.
End with one concrete update: a brain pattern, a never-submit rule, a report wording change, or a target ranking adjustment.
Version History
- 41d49b6 Current 2026-07-24 11:57


