/brain
Manage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends.
$ npx -y skills add H-mmer/pentest-agents --skill brain --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/brain
Context preview
The summary Claude sees to decide when to auto-load this skill.
Manage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends.
SKILL.md
brain.SKILL.mdname: brain
description: "Manage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends."
disable-model-invocation: false
Brain management: $ARGUMENTS
Route to the brain tool:
- If "$ARGUMENTS" is "init": run `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py init`
- If "$ARGUMENTS" starts with "brief": run `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py brief <target>`
- If "$ARGUMENTS" is "status": run `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py status`
- If "$ARGUMENTS" starts with "exhausted": run `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py exhausted <target>`
- If "$ARGUMENTS" starts with "record": run `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> <status> <technique> "<details>"`
After running, also launch the `brain` agent to update the MEMORY.md index if any state changed.
Top-Tier Memory Bar
Bad memory makes the whole suite worse. Record facts as reusable evidence, not diary entries.
For every record, include:
- `target`: canonical host or repo name
- `surface`: endpoint, file, workflow, account role, or component
- `technique`: vuln class plus variant, not just "tested auth"
- `status`: confirmed, partial, exhausted, blocked, duplicate-risk, chain-pending
- `evidence`: request id, file path, response marker, screenshot path, command output, or blocker
- `next_action`: the exact command or test a future session should run
Never store "no bug" without the tested matrix. An exhausted entry must say what was tried and why that evidence is strong enough to skip it later.
Read more
name: brain description: "Manage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends." disable-model-invocation: false
Brain management: $ARGUMENTS
Route to the brain tool:
- If "$ARGUMENTS" is "init": run `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py init`
- If "$ARGUMENTS" starts with "brief": run `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py brief <target>`
- If "$ARGUMENTS" is "status": run `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py status`
- If "$ARGUMENTS" starts with "exhausted": run `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py exhausted <target>`
- If "$ARGUMENTS" starts with "record": run `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> <status> <technique> "<details>"`
After running, also launch the `brain` agent to update the MEMORY.md index if any state changed.
Top-Tier Memory Bar
Bad memory makes the whole suite worse. Record facts as reusable evidence, not diary entries.
For every record, include:
- `target`: canonical host or repo name
- `surface`: endpoint, file, workflow, account role, or component
- `technique`: vuln class plus variant, not just "tested auth"
- `status`: confirmed, partial, exhausted, blocked, duplicate-risk, chain-pending
- `evidence`: request id, file path, response marker, screenshot path, command output, or blocker
- `next_action`: the exact command or test a future session should run
Never store "no bug" without the tested matrix. An exhausted entry must say what was tried and why that evidence is strong enough to skip it later.
Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.
Repo: H-mmer/pentest-agents
Other skills on pentest-agents.
- /analyze
Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze <target>
Open skill - /autopilot
Autonomous hunt orchestrator. INSATIABLE in --autonomous mode: enforces an EXHAUSTION CONTRACT (26 canonical hunter classes, surface probe A-I, depth-engine ≥25 attempts/class, wall-clock floor 90 min/target, PRE-COMPLETION GATE before any summary). No early stops, no clarifying
Open skill - /chain
Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)
Open skill - /correlate
Run the finding correlation engine to discover attack chains from individual findings.
Open skill - /cost
Show cost tracking and ROI for this engagement.
Open skill - /dupcheck
Check if a vulnerability has already been reported. Searches platform hacktivity + local findings. Usage: /dupcheck <vuln_type> e.g. /dupcheck XSS in search endpoint
Open skill

