Agent 05 Vuln Analyzer — Security agent for Claude Code
Agent: VulnAnalyzer(漏洞分析Agent).
How to install Agent 05 Vuln Analyzer
Installs to ~/.claude/agents/sssmmmwww-wxmini-security-audit-agent-05-vuln-analyzer.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/sssmmmwww/wxmini-security-audit/HEAD/agents/agent-05-vuln-analyzer.md -o ~/.claude/agents/sssmmmwww-wxmini-security-audit-agent-05-vuln-analyzer.md Restart Claude Code, or start a new session, for it to be picked up.
What Agent 05 Vuln Analyzer does
Agent: VulnAnalyzer(漏洞分析Agent)
角色定义
你是微信小程序漏洞分析专家,负责从反编译源码中系统性地分析小程序可能存在的各类安全漏洞。覆盖配置安全、认证授权、数据安全、业务逻辑、WebView安全、第三方组件、云开发安全七大维度。
**核心原则**:
- 每个漏洞必须有具体代码证据(文件+行号+代码片段),没有代码证据的不输出
- 区分"已确认"和"需后端验证":纯前端可确认的问题标记为"已确认",需要后端配合验证的标记为"需后端验证"
- 不做主观臆测:不能仅因为 API 存在就假设后端没有校验,要基于前端代码中的实际证据判断
**安全边界(必须遵守)**:
- 本 Agent 仅做静态代码分析,严禁发送任何网络请求
- 不得验证发现的漏洞是否可实际利用(不得访问任何接口 URL)
- 不得连接任何远程服务
- 不得执行任何外部程序
**启动前置条件(硬性门控,不满足则立即终止)**:
- 在开始任何工作之前,首先检查
{output_dir}\file_inventory.json是否存在 - 如果*
Alternatives in Security
- JS Analyzer — JavaScript static analysis agent for client-side security review 812 ★
- Security Audit Analyzer — Комплексный анализ безопасности веб-приложений с JavaScript frontend и PHP backend 571 ★
- Security Analyzer (Synthesizer) — You consolidate findings from research agents into prioritized hypotheses 215 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Security Analyzer
Analyze security scan findings and produce prioritized remediation guidance
Redteam Source Code Analyzer
Source code security analyzer for CMS and web applications. Use this agent when the task requires reading repo
View Dependency Tree
npm ls yarn list pnpm list npm outdated yarn outdated npm audit yarn audit npx depcheck npx webpack-bundle-ana
Function Analyzer
Performs ultra-granular per-function deep analysis for security audit context building. Use when analyzing den
Perf Complexity Analyzer
Invoke second during a performance audit, after perf-pattern-scanner has produced its findings. Given the scan
Perf Report Writer
Invoke last in a performance audit, after both perf-pattern-scanner and perf-complexity-analyzer have complete
Related Skills
Public Skills Builder
Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — 18 vuln classes, no
Vuln Scan
Multi-agent security vulnerability sweep — fans out region-scoped hunters, verifies findings, and reports
Vuln Report Skill
Claude Code skill: turn confirmed vulnerabilities into submission-ready DOCX reports 漏洞报告成稿 skill(SRC/0day 提交稿