/surface
Show ranked attack surface for a target. Invokes recon-ranker agent. Usage: /surface target.com
$ npx -y skills add H-mmer/pentest-agents --skill surface --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/surface
Context preview
The summary Claude sees to decide when to auto-load this skill.
Show ranked attack surface for a target. Invokes recon-ranker agent. Usage: /surface target.com
SKILL.md
surface.SKILL.mdname: surface description: "Show ranked attack surface for a target. Invokes recon-ranker agent. Usage: /surface target.com" disable-model-invocation: false
Rank attack surface for: $ARGUMENTS
1. Verify recon data exists in recon/ directory. If not, suggest /recon first. 2. Read brain data for this target. 3. Launch `recon-ranker` agent: "Rank the attack surface for $ARGUMENTS. Read recon/ for discovery data and brain for tested endpoints. Output P1/P2/Kill ranking." 4. Show the ranking to the user. 5. Suggest: `/hunt $ARGUMENTS` to start testing P1 targets.
Top-Tier Surface Ranking
Rank by exploit economics.
P1 requires at least two of:
- crown-jewel function: auth, billing, admin, tenant data, integrations, uploads, exports, webhooks, AI/tool execution
- weak boundary: cross-tenant IDs, mixed roles, public/private transition, OAuth callback, parser boundary, file ingestion
- novelty: new asset, changed JS, low hacktivity coverage, unusual vendor or beta endpoint
- proof path: two-account test, clear callback, readable response, browser-verifiable sink, local PoC
Kill or P3 assets that are static marketing pages, hardened vendor panels with no program-owned data, or endpoints already exhausted with strong evidence. Every P1 must include the best first vuln class and first request to try.
Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.
Repo: H-mmer/pentest-agents
Other skills on pentest-agents.
- /analyze
Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze <target>
Open skill - /autopilot
Autonomous hunt orchestrator. INSATIABLE in --autonomous mode: enforces an EXHAUSTION CONTRACT (26 canonical hunter classes, surface probe A-I, depth-engine ≥25 attempts/class, wall-clock floor 90 min/target, PRE-COMPLETION GATE before any summary). No early stops, no clarifying
Open skill - /brain
Manage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends.
Open skill - /chain
Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)
Open skill - /correlate
Run the finding correlation engine to discover attack chains from individual findings.
Open skill - /cost
Show cost tracking and ROI for this engagement.
Open skill

