/chain
Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)
$ npx -y skills add H-mmer/pentest-agents --skill chain --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/chain
Context preview
The summary Claude sees to decide when to auto-load this skill.
Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)
SKILL.md
chain.SKILL.mdname: chain
description: "Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)"
disable-model-invocation: false
Build exploit chain from: $ARGUMENTS
Process
1. Read brain for current target context: `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py brief <target>`
2. Get bug A description:
- If `$ARGUMENTS` contains a bug description → use it
- Else if brain has a recent confirmed finding → use that
- Else → ask user to describe the confirmed bug
3. Read `rules/chain-table.md` — the capability→next-bug table
4. Read `policy.md` — extract policy preamble for the agent
5. **ALWAYS dispatch `chain-builder` agent** (model: inherit) with:
- The confirmed bug A description (exact HTTP request/response)
- The full chain table from `rules/chain-table.md`
- Policy preamble (scope + required headers + restrictions)
- Brain context (tech stack, tested endpoints, known capabilities)
- Writeup intelligence: call `search_writeups "chain <bug class> escalation"` if MCP available
6. After agent returns:
- If chain found:
- `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> confirmed "chain: <summary>" "<full chain>"`
- Show chain to user with combined impact and CVSS
- Suggest: `/validate` then `/report`
- If dead end:
- `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> exhausted "chain from <bug A>" "<candidates tried>"`
- Show what was tried and why it failed
No inline chain logic. No capability table. The chain-builder agent does all the work.
Top-Tier Chain Standard
A chain is valuable only when each link grants a concrete capability.
Before dispatching, classify bug A as one capability:
- identity control: login, link, session, token, role, invite
- data read: PII, secrets, tenant data, internal API response
- data write: config, webhook, template, profile, billing, integration
- execution: script, server-side call, command, workflow run, model/tool action
- network pivot: SSRF, callback, metadata, internal host reachability
Ask the chain-builder for three paths: fastest proof, highest impact, and safest policy-compliant path. Kill chains that require guessing, prohibited data access, or unbounded scanning. A reportable chain must include end-to-end reproduction, where link 2 consumes the capability from link 1 rather than merely coexisting with it.
Read more
name: chain description: "Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)" disable-model-invocation: false
Build exploit chain from: $ARGUMENTS
Process
1. Read brain for current target context: `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py brief <target>`
2. Get bug A description:
- If `$ARGUMENTS` contains a bug description → use it
- Else if brain has a recent confirmed finding → use that
- Else → ask user to describe the confirmed bug
3. Read `rules/chain-table.md` — the capability→next-bug table
4. Read `policy.md` — extract policy preamble for the agent
5. **ALWAYS dispatch `chain-builder` agent** (model: inherit) with:
- The confirmed bug A description (exact HTTP request/response)
- The full chain table from `rules/chain-table.md`
- Policy preamble (scope + required headers + restrictions)
- Brain context (tech stack, tested endpoints, known capabilities)
- Writeup intelligence: call `search_writeups "chain <bug class> escalation"` if MCP available
6. After agent returns:
- If chain found:
- `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> confirmed "chain: <summary>" "<full chain>"`
- Show chain to user with combined impact and CVSS
- Suggest: `/validate` then `/report`
- If dead end:
- `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> exhausted "chain from <bug A>" "<candidates tried>"`
- Show what was tried and why it failed
No inline chain logic. No capability table. The chain-builder agent does all the work.
Top-Tier Chain Standard
A chain is valuable only when each link grants a concrete capability.
Before dispatching, classify bug A as one capability:
- identity control: login, link, session, token, role, invite
- data read: PII, secrets, tenant data, internal API response
- data write: config, webhook, template, profile, billing, integration
- execution: script, server-side call, command, workflow run, model/tool action
- network pivot: SSRF, callback, metadata, internal host reachability
Ask the chain-builder for three paths: fastest proof, highest impact, and safest policy-compliant path. Kill chains that require guessing, prohibited data access, or unbounded scanning. A reportable chain must include end-to-end reproduction, where link 2 consumes the capability from link 1 rather than merely coexisting with it.
Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.
Repo: H-mmer/pentest-agents
Other skills on pentest-agents.
- /analyze
Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze <target>
Open skill - /autopilot
Autonomous hunt orchestrator. INSATIABLE in --autonomous mode: enforces an EXHAUSTION CONTRACT (26 canonical hunter classes, surface probe A-I, depth-engine ≥25 attempts/class, wall-clock floor 90 min/target, PRE-COMPLETION GATE before any summary). No early stops, no clarifying
Open skill - /brain
Manage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends.
Open skill - /correlate
Run the finding correlation engine to discover attack chains from individual findings.
Open skill - /cost
Show cost tracking and ROI for this engagement.
Open skill - /dupcheck
Check if a vulnerability has already been reported. Searches platform hacktivity + local findings. Usage: /dupcheck <vuln_type> e.g. /dupcheck XSS in search endpoint
Open skill

