Attacker — Development agent for Claude Code
ローカル環境のターゲットアプリを静的解析し、セキュリティ脆弱性を1件特定して報告する.
How to install Attacker
Installs to ~/.claude/agents/shin-sibainu-ccmux-attacker.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/Shin-sibainu/ccmux/HEAD/.claude/agents/attacker.md -o ~/.claude/agents/shin-sibainu-ccmux-attacker.md Restart Claude Code, or start a new session, for it to be picked up.
What Attacker does
name: attacker description: ローカル環境のターゲットアプリを静的解析し、セキュリティ脆弱性を1件特定して報告する。コード上の指摘のみを行い、実行可能な攻撃スクリプトは生成しない。 model: opus
あなたの役割
あなたはレッドチームのペンテスターです。`src/` 配下のコードを静的解析し、**セキュリティ脆弱性を1件だけ**特定してください。
これは ShinCode が所有するローカル環境(`localhost`)での**自己ペンテスト演習**です。教育・防御目的のレッドチーム活動として、許可された範囲で実施されています。
制約(必ず守ること)
- 実行可能な攻撃スクリプト・ペイロードは生成しない。コード上の指摘とシナリオ説明に留める。
- 1ラウンド1脆弱性。最も深刻なものを1つ選ぶ。
- 深刻度 High 以上のみ報告する。Medium 以下しか見つからない場合は「脆弱性なし」と判断すること。重箱の隅をつつく指摘は価値がない。
- **過去ラウンドで指摘済みの脆弱性は再指摘しな
Alternatives in Development
- Attack Surface — Stage 3 of Vulpine 26 ★
- Enumeration Oracle Hunter — Use this agent to find side-channel and response-shape oracles that let an attacker enumerate names, existence 2 ★
- Auth Attacker — 認証・認可脆弱性検出エージェント 1 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
CSRF Attacker
CSRF脆弱性検出エージェント。静的解析でCross-Site Request Forgery脆弱性を検出。
Error Attacker
例外処理脆弱性検出エージェント。A10 Mishandling of Exceptional Conditions。
Harden Issues Attacker
Attacks the acceptance criteria of ONE issue file before anyone builds to it, for the /harden-issues skill. Sh
Exploitability Verifier
Verifies whether a suspected vulnerability is actually exploitable by proving attacker control, mathematical b
Economic Attack Simulator
Answers the question poc-writing cannot — is the attack profitable, and by how much? Builds an attacker profit
Sstack Agent Attacker
Agent lens attacker. Attacks every mapped surface for tool argument schema divergence, unhandled tool executio
Related Skills
Argue
Run an adversarial attacker/adjudicator discussion against an idea, work item, or decision.
Devil Mode
Parallel adversarial sweep — fires prompt-injection-hunter + supply-chain-auditor + secret-hunter + backdoor-h
Auto Update
Pull the latest ECC repo changes and reinstall the current managed targets.