analyze
Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze <target>
Source code vulnerability hunting (SAST). Decomposes analysis into specialized passes: map entry points, map dangerous ops, trace flows, find gaps, adversarial validation, exploit. Usage: /sast <repo_path> [--lang c|cpp|rust|java|python|go|php] [--min-score 4] [--max-files 30]
$ npx -y skills add H-mmer/pentest-agents --skill sast --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/sastContext preview
The summary Claude sees to decide when to auto-load this skill.
Source code vulnerability hunting (SAST). Decomposes analysis into specialized passes: map entry points, map dangerous ops, trace flows, find gaps, adversarial validation, exploit. Usage: /sast <repo_path> [--lang c|cpp|rust|java|python|go|php] [--min-score 4] [--max-files 30]
name: sast description: "Source code vulnerability hunting (SAST). Decomposes analysis into specialized passes: map entry points, map dangerous ops, trace flows, find gaps, adversarial validation, exploit. Usage: /sast <repo_path> [--lang c|cpp|rust|java|python|go|php] [--min-score 4] [--max-files 30] [--skip-static] [--best-of N]" disable-model-invocation: false
Source code hunt on: $ARGUMENTS
ALL agents dispatched by this command MUST use `model: "inherit"` in the Agent tool call, EXCEPT sast-flow-tracer and sast-gap-analyzer which MUST use `model: "opus"` (these require cross-file reasoning that benefits from maximum reasoning depth regardless of what the orchestrator inherits).
Read rules/hunting.md FIRST. Rules 0, 2, 9, 14 apply to SAST. Read skills/sast-methodology/SKILL.md for reference.
A single agent asked to "find vulnerabilities" will hallucinate plausible-looking bugs. This pipeline decomposes the task into focused steps:
1. Reading code and listing entry points → comprehension task 2. Listing dangerous operations → pattern matching task 3. Connecting entry points to dangerous ops → cross-file reasoning (pinned opus) 4. Finding validation gaps in those connections → focused analysis (pinned opus) 5. Disproving each candidate → adversarial checking 6. Building PoC for survivors → targeted coding
The synthesis happens through the PIPELINE, not inside one agent's head.
1. Parse args: `<repo_path>`, `--lang` (auto-detect), `--min-score` (default 4), `--max-files` (default 30), `--skip-static` (skip CodeQL/Semgrep), `--best-of N` (run N independent hunters on top files, default 1) 2. `ls <repo_path>/` 3. Auto-detect language:
find <repo_path> \( -name '*.c' -o -name '*.cpp' -o -name '*.h' -o -name '*.rs' -o -name '*.java' -o -name '*.py' -o -name '*.go' -o -name '*.php' -o -name '*.phtml' -o -name '*.inc' \) | head -20
4. Check build: `ls <repo_path>/{Makefile,CMakeLists.txt,Cargo.toml,pom.xml,go.mod,composer.json} 2>/dev/null` 5. Brain: `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py brief sast-<repo_name>` 6. Create output dirs: `mkdir -p findings/sast poc/sast/exploits sast-work/`
cd <repo_path> export CC="gcc" CFLAGS="-fsanitize=address,undefined -g -O1 -fno-omit-frame-pointer" export CXX="g++" CXXFLAGS="$CFLAGS"
If build fails → log and continue. Code review still works.
**Skip 1a for PHP/Python/Java** — no native sanitizers. For PHP, ensure `php --version` works and, if `composer.json` exists, run `composer install --no-dev` best-effort for autoload/deps.
Run available tools and collect warnings:
# C/C++ cppcheck --enable=all --xml <repo_path> 2> sast-work/cppcheck.xml # Universal semgrep --config auto <repo_path> -o sast-work/semgrep.json --json # PHP (run these when --lang php or .php files detected) semgrep --config p/php --config p/security-audit <repo_path> -o sast-work/semgrep-php.json --json psalm --taint-analysis --output-format=json <repo_path> > sast-work/psalm.json 2>/dev/null || true phpstan analyse --level=max --error-format=json <repo_path> > sast-work/phpstan.json 2>/dev/null || true
Parse into `sast-work/static-warnings.json`. These feed into Phase 3d as additional candidates.
Dispatch `sast-file-ranker` agent (model: inherit):
For each file scoring >= `--min-score`, starting from highest:
Dispatch `sast-entry-mapper` agent (model: inherit):
Dispatch `sast-danger-mapper` agent (model: inherit):
Dispatch `sast-flow-tracer` agent (model: **opus**):
Dispatch `sast-gap-analyzer` agent (model: **opus**):
`uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record sast-<repo_name> analyzed "<file>" "entries: N, dangers: N, flows: N, candidates: N"`
For each candidate: Dispatch `sast-devils-advocate` agent (model: inherit):
For each survivor: Dispatch `sast-hunter` agent (model: inherit) in focused mode:
For score-5 files, run N independent instances. Finding in 2+ runs = real. Finding in 1 run = flag for review.
Dispatch `sast-exploit-builder` agent (model: inherit):
Record to brain, write to `findings/sast/`, print summary.
SAST HUNT: <repo_name> (decomposed pipeline) ══════════════════════════════════════════════ Static warnings: N | Files ranked: N (huntable: N) Entry points: N | Dangerous ops: N | Reachable flows: N | Candidates: N Devil's advocate: N survived / N killed ASan confirmed: N | Exploit tiers: ... CONFIRMED: 1. [CRITICAL] <title> — <file>:<line> Flow: <entry> → <gap> → <dangerous op> HALLUCINATIONS CAUGHT (saved by devil's advocate): - <candidate> — killed: <reason> Cost: $X.XX | Agents: N
4-6 agents per file, two using Opus. Budget ~$0.50-2.00/file. 30 files ≈ $15-60. Adjust --min-score and --max-files accordin
Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.
Repo: H-mmer/pentest-agents
Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze <target>
Autonomous hunt orchestrator. INSATIABLE in --autonomous mode: enforces an EXHAUSTION CONTRACT (26 canonical hunter classes, surface probe A-I, depth-engine…
Manage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends.
Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)
Run the finding correlation engine to discover attack chains from individual findings.