analyze

GitHub

基于侦察数据,利用AI分析高价值目标与攻击策略。通过映射核心资产、排序攻击路径及检测盲区,生成包含具体验证命令的实战建议,指导后续渗透测试。

providers/codex/.agents/skills/analyze/SKILL.md H-mmer/pentest-agents

Trigger Scenarios

用户请求分析特定目标的潜在漏洞 需要制定渗透测试计划或寻找未覆盖的攻击面 希望获得基于技术栈和情报的高优先级攻击路径推荐

Install

npx skills add H-mmer/pentest-agents --skill analyze -g -y
More Options

Non-standard path

npx skills add https://github.com/H-mmer/pentest-agents/tree/main/providers/codex/.agents/skills/analyze -g -y

Use without installing

npx skills use H-mmer/pentest-agents@analyze

指定 Agent (Claude Code)

npx skills add H-mmer/pentest-agents --skill analyze -a claude-code -g -y

安装 repo 全部 skill

npx skills add H-mmer/pentest-agents --all -g -y

预览 repo 内 skill

npx skills add H-mmer/pentest-agents --list

SKILL.md

Frontmatter
{
    "name": "analyze",
    "description": "Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: \/analyze <target>"
}

AI-powered analysis of recon data for: $ARGUMENTS

Process

  1. Read all recon data: ls recon/ and read key files
  2. Read brain data: uv run python3 ../../tools/brain.py brief $ARGUMENTS
  3. Read tech stack intel: uv run python3 ../../tools/intel_engine.py suggest <detected-stack>
  4. Read hacktivity patterns: uv run python3 ../../tools/intel_engine.py analyze

Analysis Tasks (do all of these)

Crown Jewel Mapping

What's the most valuable thing an attacker could access on this target?

  • Financial data? → hunt IDOR on payment/billing endpoints
  • User PII? → hunt IDOR on profile/export endpoints
  • Admin access? → hunt auth bypass on admin endpoints
  • Infrastructure? → hunt SSRF → cloud metadata

Attack Path Ranking

Given the tech stack and recon output, rank the top 5 attack paths by:

  1. Likelihood of vulnerability existing (based on tech stack patterns)
  2. Impact if exploited (based on endpoint function)
  3. Competition (based on hacktivity — avoid heavily-reported vuln classes)
  4. Your past success (from brain patterns)

Blind Spot Detection

What has NOT been tested? What endpoints have no brain data? Cross-reference recon output against brain tested endpoints. Flag untested high-value endpoints.

Output

ANALYSIS: target.com
═════════════════════

Crown Jewels: [what's most valuable]

Top 5 Attack Paths:
1. [endpoint] × [vuln class] — likelihood: HIGH, impact: CRITICAL
2. ...

Blind Spots (untested P1 surface):
- /api/v2/payments/* — NO DATA in brain
- /api/v2/admin/* — NO DATA in brain

Recommendation: /hunt target.com --vuln-class [best bet]

Top-Tier Operator Addendum

Treat /analyze as a thesis generator, not a summary command. The output must make the next hour of hunting obvious.

  1. Build a weighted table before recommending anything:
    • asset_value: revenue, PII, admin, secrets, infrastructure, tenant boundary
    • exploit_likelihood: stack age, exposed methods, auth complexity, parser surface, prior bug class fit
    • novelty: low hacktivity overlap, new endpoint, changed JS, unusual integration, weak vendor pattern
    • proof_path: exact request needed to prove impact, required accounts, required evidence artifact
    • policy_friction: rate limits, forbidden data access, third-party scope, credential validation rules
  2. Prefer attack paths with a short proof path over impressive theory. A boring IDOR with two accounts and a readback beats a speculative SSRF with no egress signal.
  3. Include negative evidence. If /api/admin/* looks valuable but all routes are 403 with no differential, say that and explain what would change the ranking.
  4. Separate P1 now, P2 if time, and Kill for this session. Top-tier analysis saves time by deleting tempting dead ends.
  5. Every recommendation must name the next command and the exact first test: /hunt target --vuln-class idor plus the endpoint pair, account pair, and field to compare.

Version History

  • 41d49b6 Current 2026-07-24 11:57

Same Skill Collection

.claude/skills/analyze/SKILL.md
.claude/skills/autopilot/SKILL.md
.claude/skills/brain/SKILL.md
.claude/skills/chain/SKILL.md
.claude/skills/correlate/SKILL.md
.claude/skills/dupcheck/SKILL.md
.claude/skills/fullscan/SKILL.md
.claude/skills/hunt/SKILL.md
.claude/skills/learn/SKILL.md
.claude/skills/mindmap/SKILL.md
.claude/skills/monitor/SKILL.md
.claude/skills/new/SKILL.md
.claude/skills/pipeline/SKILL.md
.claude/skills/quality/SKILL.md
.claude/skills/quickscan/SKILL.md
.claude/skills/remember/SKILL.md
.claude/skills/report/SKILL.md
.claude/skills/resume/SKILL.md
.claude/skills/sast/SKILL.md
.claude/skills/status/SKILL.md
.claude/skills/submit/SKILL.md
.claude/skills/surface/SKILL.md
.claude/skills/sync/SKILL.md
.claude/skills/triage/SKILL.md
.claude/skills/validate/SKILL.md
providers/codex/.agents/skills/autopilot/SKILL.md
providers/codex/.agents/skills/brain/SKILL.md
providers/codex/.agents/skills/chain/SKILL.md
providers/codex/.agents/skills/correlate/SKILL.md
providers/codex/.agents/skills/dupcheck/SKILL.md
providers/codex/.agents/skills/fullscan/SKILL.md
providers/codex/.agents/skills/hunt/SKILL.md
providers/codex/.agents/skills/learn/SKILL.md
providers/codex/.agents/skills/mindmap/SKILL.md
providers/codex/.agents/skills/monitor/SKILL.md
providers/codex/.agents/skills/new/SKILL.md
providers/codex/.agents/skills/pipeline/SKILL.md
providers/codex/.agents/skills/quality/SKILL.md
providers/codex/.agents/skills/quickscan/SKILL.md
providers/codex/.agents/skills/remember/SKILL.md
providers/codex/.agents/skills/report/SKILL.md
providers/codex/.agents/skills/resume/SKILL.md
providers/codex/.agents/skills/sast/SKILL.md
providers/codex/.agents/skills/status/SKILL.md
providers/codex/.agents/skills/submit/SKILL.md
providers/codex/.agents/skills/surface/SKILL.md
providers/codex/.agents/skills/sync/SKILL.md
providers/codex/.agents/skills/triage/SKILL.md
providers/codex/.agents/skills/validate/SKILL.md

Metadata

Files
0
Version
41d49b6
Hash
2079f773
Indexed
2026-07-24 11:57

- 위키
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-07 01:34
浙ICP备14020137号-1 $방문자$