Agent Skills
› H-mmer/pentest-agents
› resume
resume
GitHub恢复之前的安全狩猎任务,通过读取大脑记忆、链挂起建议和侦察数据,展示已测/未测端点。基于价值而非时间优先排序,提供智能下一步建议及操作选项。
Trigger Scenarios
用户输入 /resume 命令
需要继续上次的漏洞挖掘会话
Install
npx skills add H-mmer/pentest-agents --skill resume -g -y
SKILL.md
Frontmatter
{
"name": "resume",
"description": "Resume a previous hunt. Shows hunt history, untested endpoints, memory-informed suggestions. Usage: \/resume target.com"
}
Resume hunt on: $ARGUMENTS
What This Does
- Read brain for target:
uv run python3 ../../tools/brain.py brief $ARGUMENTS - Read brain exhausted:
uv run python3 ../../tools/brain.py exhausted $ARGUMENTS - Read chain-pending advisory:
cat .claude/agent-memory-local/chain-pending.md 2>/dev/null— feeder findings from prior session waiting for chain dispatch. SURFACE THESE FIRST — they have proven dollar value if chained, vs untested surface which is speculative. - Generate / refresh chain plan:
uv run python3 ../../tools/chain_plan.py $ARGUMENTS— writesevidence/<target>/CHAIN_PLAN.mdwith 3-5 candidate next-links per pending feeder finding plus the agent to dispatch for each. Read this BEFORE picking the next vuln class — proven feeders trump speculative untested surface. - Read recon data from recon/ directory
- Show what's been tested vs what remains
- Suggest next techniques based on brain patterns
Output
RESUME: target.com
═══════════════════
Brain Status:
Confirmed findings: N
Exhausted techniques: N
Effective techniques: N
Untested Surface:
1. /api/v2/users/{id}/export — not tested
2. /api/v2/users/{id}/share — not tested
...
Suggestions:
- Tech stack [X] matches pattern where IDOR was found before
- Sibling endpoints of confirmed finding not yet tested
Actions:
[h] /hunt target.com — resume hunting
[s] /surface target.com — re-rank attack surface
[r] /recon target.com — re-run recon (surface may have changed)
[m] /monitor check — check for target changes since last session
Top-Tier Resume Logic
Resume by value, not chronology.
Priority order:
chain-pendingconfirmed feeders with clear next link- validated partials needing one proof artifact
- changed assets from
/monitor - untested P1 crown-jewel endpoints
- high-confidence class hypotheses from prior wins
- stale recon refresh
Show what not to redo. If an area is exhausted, include the exact blocker and matrix coverage. A resumed hunt should start with a single best command, not a menu of every possible command.
Version History
- 41d49b6 Current 2026-07-24 11:58


