Generate attack surface mindmap for: $ARGUMENTS
Process
- Read brain data:
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py brief $ARGUMENTS
- Read recon data from recon/ directory
- Read intel data:
uv run python3 $CLAUDE_PROJECT_DIR/tools/intel_engine.py suggest <tech-stack>
- Generate a tree-format mindmap:
target.com
├── Tech Stack
│ ├── Next.js 14 → SSRF (Server Actions), Open Redirect
│ ├── GraphQL → Introspection, IDOR via node(), Mutation Auth
│ └── PostgreSQL → SQL Injection
├── Auth
│ ├── Okta SSO → SAML bypass, OAuth redirect_uri
│ └── JWT → Secret brute-force, Algorithm confusion
├── API Surface
│ ├── /api/v2/users/{id}/* → IDOR (P1)
│ │ ├── /orders — TESTED: exhausted
│ │ ├── /export — UNTESTED
│ │ └── /settings — UNTESTED
│ ├── /api/v2/payments/* → Race conditions, price manipulation (P1)
│ └── /graphql → Auth bypass on mutations (P1)
├── File Handling
│ └── /upload → Extension bypass, SVG XSS (P2)
└── Findings
├── [CONFIRMED] IDOR on /api/v2/users/{id}/orders
└── [EXHAUSTED] XSS on /search — CloudFront blocks all payloads
- Mark each endpoint as TESTED, UNTESTED, CONFIRMED, or EXHAUSTED from brain data
- Suggest: "Start with UNTESTED P1 endpoints. Run /hunt $ARGUMENTS --vuln-class "
Top-Tier Mindmap Standard
The mindmap should expose attack decisions at a glance.
- Group by trust boundary first: unauth, user, tenant, admin, integration, internal, CI/CD, AI/tool.
- Mark every node with one of:
P1, P2, Kill, Confirmed, Partial, Exhausted, Chain.
- Draw capability edges, not just URL hierarchy: export reads data, webhook sends server-side request, template renders attacker input, OAuth callback grants token.
- Surface blind spots explicitly: "no second-account test", "no browser verification", "no sibling replay", "no chain attempt".
- End with the top three routes where one more test could change severity or reportability.
1---2name: mindmap3description: Generate a text-based attack surface mindmap. Shows tech stack → vuln class → endpoint relationships. Usage: /mindmap <target>4---5Generate attack surface mindmap for: $ARGUMENTS67## Process81. Read brain data: `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py brief $ARGUMENTS`92. Read recon data from recon/ directory103. Read intel data: `uv run python3 $CLAUDE_PROJECT_DIR/tools/intel_engine.py suggest <tech-stack>`114. Generate a tree-format mindmap:1213```14target.com15├── Tech Stack16│ ├── Next.js 14 → SSRF (Server Actions), Open Redirect17│ ├── GraphQL → Introspection, IDOR via node(), Mutation Auth18│ └── PostgreSQL → SQL Injection19├── Auth20│ ├── Okta SSO → SAML bypass, OAuth redirect_uri21│ └── JWT → Secret brute-force, Algorithm confusion22├── API Surface23│ ├── /api/v2/users/{id}/* → IDOR (P1)24│ │ ├── /orders — TESTED: exhausted25│ │ ├── /export — UNTESTED26│ │ └── /settings — UNTESTED27│ ├── /api/v2/payments/* → Race conditions, price manipulation (P1)28│ └── /graphql → Auth bypass on mutations (P1)29├── File Handling30│ └── /upload → Extension bypass, SVG XSS (P2)31└── Findings32 ├── [CONFIRMED] IDOR on /api/v2/users/{id}/orders33 └── [EXHAUSTED] XSS on /search — CloudFront blocks all payloads34```35365. Mark each endpoint as TESTED, UNTESTED, CONFIRMED, or EXHAUSTED from brain data376. Suggest: "Start with UNTESTED P1 endpoints. Run /hunt $ARGUMENTS --vuln-class <suggested>"3839## Top-Tier Mindmap Standard4041The mindmap should expose attack decisions at a glance.4243- Group by trust boundary first: unauth, user, tenant, admin, integration, internal, CI/CD, AI/tool.44- Mark every node with one of: `P1`, `P2`, `Kill`, `Confirmed`, `Partial`, `Exhausted`, `Chain`.45- Draw capability edges, not just URL hierarchy: export reads data, webhook sends server-side request, template renders attacker input, OAuth callback grants token.46- Surface blind spots explicitly: "no second-account test", "no browser verification", "no sibling replay", "no chain attempt".47- End with the top three routes where one more test could change severity or reportability.