analyze
Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze <target>
Show ranked attack surface for a target. Invokes recon-ranker agent. Usage: /surface target.com
$ npx -y skills add H-mmer/pentest-agents --skill surface --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/surfaceContext preview
The summary Claude sees to decide when to auto-load this skill.
Show ranked attack surface for a target. Invokes recon-ranker agent. Usage: /surface target.com
name: surface description: "Show ranked attack surface for a target. Invokes recon-ranker agent. Usage: /surface target.com" disable-model-invocation: false
Rank attack surface for: $ARGUMENTS
1. Verify recon data exists in recon/ directory. If not, suggest /recon first. 2. Read brain data for this target. 3. Launch `recon-ranker` agent: "Rank the attack surface for $ARGUMENTS. Read recon/ for discovery data and brain for tested endpoints. Output P1/P2/Kill ranking." 4. Show the ranking to the user. 5. Suggest: `/hunt $ARGUMENTS` to start testing P1 targets.
Rank by exploit economics.
P1 requires at least two of:
Kill or P3 assets that are static marketing pages, hardened vendor panels with no program-owned data, or endpoints already exhausted with strong evidence. Every P1 must include the best first vuln class and first request to try.
Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.
Repo: H-mmer/pentest-agents
Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze <target>
Autonomous hunt orchestrator. INSATIABLE in --autonomous mode: enforces an EXHAUSTION CONTRACT (26 canonical hunter classes, surface probe A-I, depth-engine…
Manage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends.
Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)
Run the finding correlation engine to discover attack chains from individual findings.