analyze

GitHub

利用AI分析侦察数据,识别高价值目标并推荐攻击策略。通过映射皇冠宝石、排名攻击路径及检测盲区,结合权重评估生成可执行的狩猎建议,辅助红队高效发现漏洞。

.claude/skills/analyze/SKILL.md H-mmer/pentest-agents

触发场景

用户请求对目标进行安全分析或策略规划 输入包含 /analyze 命令后跟目标地址

安装

npx skills add H-mmer/pentest-agents --skill analyze -g -y
更多选项

非标准路径

npx skills add https://github.com/H-mmer/pentest-agents/tree/main/.claude/skills/analyze -g -y

不安装直接使用

npx skills use H-mmer/pentest-agents@analyze

指定 Agent (Claude Code)

npx skills add H-mmer/pentest-agents --skill analyze -a claude-code -g -y

安装 repo 全部 skill

npx skills add H-mmer/pentest-agents --all -g -y

预览 repo 内 skill

npx skills add H-mmer/pentest-agents --list

SKILL.md

Frontmatter
{
    "name": "analyze",
    "description": "Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: \/analyze <target>",
    "disable-model-invocation": false
}

AI-powered analysis of recon data for: $ARGUMENTS

Process

  1. Read all recon data: ls recon/ and read key files
  2. Read brain data: uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py brief $ARGUMENTS
  3. Read tech stack intel: uv run python3 $CLAUDE_PROJECT_DIR/tools/intel_engine.py suggest <detected-stack>
  4. Read hacktivity patterns: uv run python3 $CLAUDE_PROJECT_DIR/tools/intel_engine.py analyze

Analysis Tasks (do all of these)

Crown Jewel Mapping

What's the most valuable thing an attacker could access on this target?

  • Financial data? → hunt IDOR on payment/billing endpoints
  • User PII? → hunt IDOR on profile/export endpoints
  • Admin access? → hunt auth bypass on admin endpoints
  • Infrastructure? → hunt SSRF → cloud metadata

Attack Path Ranking

Given the tech stack and recon output, rank the top 5 attack paths by:

  1. Likelihood of vulnerability existing (based on tech stack patterns)
  2. Impact if exploited (based on endpoint function)
  3. Competition (based on hacktivity — avoid heavily-reported vuln classes)
  4. Your past success (from brain patterns)

Blind Spot Detection

What has NOT been tested? What endpoints have no brain data? Cross-reference recon output against brain tested endpoints. Flag untested high-value endpoints.

Output

ANALYSIS: target.com
═════════════════════

Crown Jewels: [what's most valuable]

Top 5 Attack Paths:
1. [endpoint] × [vuln class] — likelihood: HIGH, impact: CRITICAL
2. ...

Blind Spots (untested P1 surface):
- /api/v2/payments/* — NO DATA in brain
- /api/v2/admin/* — NO DATA in brain

Recommendation: /hunt target.com --vuln-class [best bet]

Top-Tier Operator Addendum

Treat /analyze as a thesis generator, not a summary command. The output must make the next hour of hunting obvious.

  1. Build a weighted table before recommending anything:
    • asset_value: revenue, PII, admin, secrets, infrastructure, tenant boundary
    • exploit_likelihood: stack age, exposed methods, auth complexity, parser surface, prior bug class fit
    • novelty: low hacktivity overlap, new endpoint, changed JS, unusual integration, weak vendor pattern
    • proof_path: exact request needed to prove impact, required accounts, required evidence artifact
    • policy_friction: rate limits, forbidden data access, third-party scope, credential validation rules
  2. Prefer attack paths with a short proof path over impressive theory. A boring IDOR with two accounts and a readback beats a speculative SSRF with no egress signal.
  3. Include negative evidence. If /api/admin/* looks valuable but all routes are 403 with no differential, say that and explain what would change the ranking.
  4. Separate P1 now, P2 if time, and Kill for this session. Top-tier analysis saves time by deleting tempting dead ends.
  5. Every recommendation must name the next command and the exact first test: /hunt target --vuln-class idor plus the endpoint pair, account pair, and field to compare.

版本历史

  • 41d49b6 当前 2026-07-24 11:56

同 Skill 集合

.claude/skills/autopilot/SKILL.md
.claude/skills/brain/SKILL.md
.claude/skills/chain/SKILL.md
.claude/skills/correlate/SKILL.md
.claude/skills/dupcheck/SKILL.md
.claude/skills/fullscan/SKILL.md
.claude/skills/hunt/SKILL.md
.claude/skills/learn/SKILL.md
.claude/skills/mindmap/SKILL.md
.claude/skills/monitor/SKILL.md
.claude/skills/new/SKILL.md
.claude/skills/pipeline/SKILL.md
.claude/skills/quality/SKILL.md
.claude/skills/quickscan/SKILL.md
.claude/skills/remember/SKILL.md
.claude/skills/report/SKILL.md
.claude/skills/resume/SKILL.md
.claude/skills/sast/SKILL.md
.claude/skills/status/SKILL.md
.claude/skills/submit/SKILL.md
.claude/skills/surface/SKILL.md
.claude/skills/sync/SKILL.md
.claude/skills/triage/SKILL.md
.claude/skills/validate/SKILL.md
providers/codex/.agents/skills/analyze/SKILL.md
providers/codex/.agents/skills/autopilot/SKILL.md
providers/codex/.agents/skills/brain/SKILL.md
providers/codex/.agents/skills/chain/SKILL.md
providers/codex/.agents/skills/correlate/SKILL.md
providers/codex/.agents/skills/dupcheck/SKILL.md
providers/codex/.agents/skills/fullscan/SKILL.md
providers/codex/.agents/skills/hunt/SKILL.md
providers/codex/.agents/skills/learn/SKILL.md
providers/codex/.agents/skills/mindmap/SKILL.md
providers/codex/.agents/skills/monitor/SKILL.md
providers/codex/.agents/skills/new/SKILL.md
providers/codex/.agents/skills/pipeline/SKILL.md
providers/codex/.agents/skills/quality/SKILL.md
providers/codex/.agents/skills/quickscan/SKILL.md
providers/codex/.agents/skills/remember/SKILL.md
providers/codex/.agents/skills/report/SKILL.md
providers/codex/.agents/skills/resume/SKILL.md
providers/codex/.agents/skills/sast/SKILL.md
providers/codex/.agents/skills/status/SKILL.md
providers/codex/.agents/skills/submit/SKILL.md
providers/codex/.agents/skills/surface/SKILL.md
providers/codex/.agents/skills/sync/SKILL.md
providers/codex/.agents/skills/triage/SKILL.md
providers/codex/.agents/skills/validate/SKILL.md

元信息

文件数
0
版本
41d49b6
Hash
f7691529
收录时间
2026-07-24 11:56

首页 - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-07 16:27
浙ICP备14020137号-1 $访客地图$