sync

GitHub

同步Bug Bounty平台(如HackerOne、Bugcrowd)的资产范围、安全策略及漏洞活动数据。通过MCP工具获取并解析信息,更新本地知识库,总结优先级与饱和区域,为渗透测试提供情报支持。

providers/codex/.agents/skills/sync/SKILL.md H-mmer/pentest-agents

Trigger Scenarios

用户输入 /sync 命令后跟平台和程序名称 需要获取或更新特定目标的安全范围和奖励机制信息

Install

npx skills add H-mmer/pentest-agents --skill sync -g -y
More Options

Non-standard path

npx skills add https://github.com/H-mmer/pentest-agents/tree/main/providers/codex/.agents/skills/sync -g -y

Use without installing

npx skills use H-mmer/pentest-agents@sync

指定 Agent (Claude Code)

npx skills add H-mmer/pentest-agents --skill sync -a claude-code -g -y

安装 repo 全部 skill

npx skills add H-mmer/pentest-agents --all -g -y

预览 repo 内 skill

npx skills add H-mmer/pentest-agents --list

SKILL.md

Frontmatter
{
    "name": "sync",
    "description": "Sync program scope, policy, and hacktivity from a bug bounty platform. Usage: \/sync hackerone tesla or \/sync bugcrowd uber"
}

Sync bug bounty program data: $ARGUMENTS

Parse the arguments as: <program_handle>

  1. Use the bounty-platforms MCP server tool sync_program with the platform and program handle. This fetches scope, policy, and hacktivity and writes them to the current directory.
  2. After sync completes, run uv run python3 ../../tools/brain.py init if brain isn't initialized yet.
  3. Read the generated scope.yaml and hacktivity.md files.
  4. Update the brain with key intelligence from hacktivity:
    • Run uv run python3 ../../tools/brain.py log "Synced program data from <platform>/<program>"
    • If hacktivity shows common vulnerability types, note them as priority areas
    • If hacktivity shows many duplicates of a type, note them as areas to avoid
  5. Summarize: scope overview, policy highlights (restrictions, safe harbor), and hacktivity patterns (most common vuln types, average bounties).

Top-Tier Sync Standard

Policy is hunting input, not paperwork.

Extract and persist:

  • exact in-scope assets, wildcard rules, mobile/API/cloud qualifiers, and third-party exclusions
  • required headers, user-agent, testing accounts, sandbox rules, rate limits, and forbidden actions
  • severity exclusions and never-pay classes
  • payout hints from hacktivity: accepted classes, duplicate-heavy classes, bounty tiers, triage language
  • newly added or removed assets since last sync

End with a hunt bias: where the program appears to pay, where it appears saturated, and what proof standard the policy implies.

Version History

  • 41d49b6 Current 2026-07-24 11:58

Same Skill Collection

.claude/skills/analyze/SKILL.md
.claude/skills/autopilot/SKILL.md
.claude/skills/brain/SKILL.md
.claude/skills/chain/SKILL.md
.claude/skills/correlate/SKILL.md
.claude/skills/dupcheck/SKILL.md
.claude/skills/fullscan/SKILL.md
.claude/skills/hunt/SKILL.md
.claude/skills/learn/SKILL.md
.claude/skills/mindmap/SKILL.md
.claude/skills/monitor/SKILL.md
.claude/skills/new/SKILL.md
.claude/skills/pipeline/SKILL.md
.claude/skills/quality/SKILL.md
.claude/skills/quickscan/SKILL.md
.claude/skills/remember/SKILL.md
.claude/skills/report/SKILL.md
.claude/skills/resume/SKILL.md
.claude/skills/sast/SKILL.md
.claude/skills/status/SKILL.md
.claude/skills/submit/SKILL.md
.claude/skills/surface/SKILL.md
.claude/skills/sync/SKILL.md
.claude/skills/triage/SKILL.md
.claude/skills/validate/SKILL.md
providers/codex/.agents/skills/analyze/SKILL.md
providers/codex/.agents/skills/autopilot/SKILL.md
providers/codex/.agents/skills/brain/SKILL.md
providers/codex/.agents/skills/chain/SKILL.md
providers/codex/.agents/skills/correlate/SKILL.md
providers/codex/.agents/skills/dupcheck/SKILL.md
providers/codex/.agents/skills/fullscan/SKILL.md
providers/codex/.agents/skills/hunt/SKILL.md
providers/codex/.agents/skills/learn/SKILL.md
providers/codex/.agents/skills/mindmap/SKILL.md
providers/codex/.agents/skills/monitor/SKILL.md
providers/codex/.agents/skills/new/SKILL.md
providers/codex/.agents/skills/pipeline/SKILL.md
providers/codex/.agents/skills/quality/SKILL.md
providers/codex/.agents/skills/quickscan/SKILL.md
providers/codex/.agents/skills/remember/SKILL.md
providers/codex/.agents/skills/report/SKILL.md
providers/codex/.agents/skills/resume/SKILL.md
providers/codex/.agents/skills/sast/SKILL.md
providers/codex/.agents/skills/status/SKILL.md
providers/codex/.agents/skills/submit/SKILL.md
providers/codex/.agents/skills/surface/SKILL.md
providers/codex/.agents/skills/triage/SKILL.md
providers/codex/.agents/skills/validate/SKILL.md

Metadata

Files
0
Version
41d49b6
Hash
9eae3e7a
Indexed
2026-07-24 11:58

- 위키
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-06 17:28
浙ICP备14020137号-1 $방문자$