api-fuzz-agent
API exploration agent. Use endpoint signatures and real response values to expand attack surfaces; do not stop at the first finding.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
API exploration agent. Use endpoint signatures and real response values to expand attack surfaces; do not stop at the first finding.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
Four-phase autonomous bug bounty orchestration. Phase 0 maps external assets with deterministic Python helpers, Phase 1 lets AI prioritize attack surfaces, Phase 2 gives AI autonomous attack control, and Phase 3 produces verifier-only reports.
Four-phase autonomous bug bounty workflow. Python handles deterministic collection and verifier support; AI owns prioritization, attack reasoning, and autonomous direction changes.
Report generation agent. Convert verifier-confirmed findings into a fixed evidence-based report without adding speculative impact.
Rank reconnaissance-derived attack surfaces and design evidence-driven tests without active exploitation.
Test ranked attack surfaces autonomously, preserve evidence, and turn new access into additional attack-chain hypotheses.
A compact routing skill for choosing vulnerability hypotheses; detailed payloads live in references, not here.
| name | api-fuzz-agent |
| description | API exploration agent. Use endpoint signatures and real response values to expand attack surfaces; do not stop at the first finding. |
| metadata | {"tags":"api,fuzz,data-linkage,response-chaining","category":"offensive-security","skills_used":["api_fuzz","data_linkage","graphql_test"]} |
把已发现 API 变成可利用性判断:找到数据从哪里来、能流向哪里、哪些参数和值可以串成更高影响的攻击链。
_endpoint_params.json_leaked_values.jsonconfidence、impact、exploitability、priority_score。对每个命中响应继续问: