Build exploit chain from: $ARGUMENTS
Process
Read brain for current target context:
uv run python3 ../../tools/brain.py brief <target>
Get bug A description:
- If
$ARGUMENTS contains a bug description → use it
- Else if brain has a recent confirmed finding → use that
- Else → ask user to describe the confirmed bug
Read rules/chain-table.md — the capability→next-bug table
Read policy.md — extract policy preamble for the agent
ALWAYS dispatch chain-builder agent (model: inherit) with:
- The confirmed bug A description (exact HTTP request/response)
- The full chain table from
rules/chain-table.md
- Policy preamble (scope + required headers + restrictions)
- Brain context (tech stack, tested endpoints, known capabilities)
- Writeup intelligence: call
search_writeups "chain <bug class> escalation" if MCP available
After agent returns:
- If chain found:
uv run python3 ../../tools/brain.py record <target> confirmed "chain: <summary>" "<full chain>"
- Show chain to user with combined impact and CVSS
- Suggest:
/validate then /report
- If dead end:
uv run python3 ../../tools/brain.py record <target> exhausted "chain from <bug A>" "<candidates tried>"
- Show what was tried and why it failed
No inline chain logic. No capability table. The chain-builder agent does all the work.
Top-Tier Chain Standard
A chain is valuable only when each link grants a concrete capability.
Before dispatching, classify bug A as one capability:
- identity control: login, link, session, token, role, invite
- data read: PII, secrets, tenant data, internal API response
- data write: config, webhook, template, profile, billing, integration
- execution: script, server-side call, command, workflow run, model/tool action
- network pivot: SSRF, callback, metadata, internal host reachability
Ask the chain-builder for three paths: fastest proof, highest impact, and safest policy-compliant path. Kill chains that require guessing, prohibited data access, or unbounded scanning. A reportable chain must include end-to-end reproduction, where link 2 consumes the capability from link 1 rather than merely coexisting with it.
1---2name: chain-23description: Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)4---56Build exploit chain from: $ARGUMENTS78## Process9101. Read brain for current target context:11 `uv run python3 ../../tools/brain.py brief <target>`12132. Get bug A description:14 - If `$ARGUMENTS` contains a bug description → use it15 - Else if brain has a recent confirmed finding → use that16 - Else → ask user to describe the confirmed bug17183. Read `rules/chain-table.md` — the capability→next-bug table19204. Read `policy.md` — extract policy preamble for the agent21225. **ALWAYS dispatch `chain-builder` agent** (model: inherit) with:23 - The confirmed bug A description (exact HTTP request/response)24 - The full chain table from `rules/chain-table.md`25 - Policy preamble (scope + required headers + restrictions)26 - Brain context (tech stack, tested endpoints, known capabilities)27 - Writeup intelligence: call `search_writeups "chain <bug class> escalation"` if MCP available28296. After agent returns:30 - If chain found:31 - `uv run python3 ../../tools/brain.py record <target> confirmed "chain: <summary>" "<full chain>"`32 - Show chain to user with combined impact and CVSS33 - Suggest: `/validate` then `/report`34 - If dead end:35 - `uv run python3 ../../tools/brain.py record <target> exhausted "chain from <bug A>" "<candidates tried>"`36 - Show what was tried and why it failed3738No inline chain logic. No capability table. The chain-builder agent does all the work.3940## Top-Tier Chain Standard4142A chain is valuable only when each link grants a concrete capability.4344Before dispatching, classify bug A as one capability:45- identity control: login, link, session, token, role, invite46- data read: PII, secrets, tenant data, internal API response47- data write: config, webhook, template, profile, billing, integration48- execution: script, server-side call, command, workflow run, model/tool action49- network pivot: SSRF, callback, metadata, internal host reachability5051Ask the chain-builder for three paths: fastest proof, highest impact, and safest policy-compliant path. Kill chains that require guessing, prohibited data access, or unbounded scanning. A reportable chain must include end-to-end reproduction, where link 2 consumes the capability from link 1 rather than merely coexisting with it.