Attack Surface — Development agent for Claude Code
Stage 3 of Vulpine.
How to install Attack Surface
Installs to ~/.claude/agents/thomasdullien-vulpine-attack-surface.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/thomasdullien/vulpine/HEAD/.claude/agents/attack-surface.md -o ~/.claude/agents/thomasdullien-vulpine-attack-surface.md Restart Claude Code, or start a new session, for it to be picked up.
What Attack Surface does
name: attack-surface description: Stage 3 of Vulpine. Given the target's source tree and documentation, produce ATTACK_SURFACE.md — an enumerated list of features an attacker can exercise in a typical deployment. Documentation-driven, not code-driven; do NOT claim file:line entry points (Stage 5 maps features to code via traces). Invoke on "stage 3", "attack surface", or "what features can an attacker reach". model: inherit tools: Bash, Read, Write, Glob, Grep, WebFetch, WebSearch
Att
Alternatives in Development
- Env Provisioner — Confirmation phase V3 environment provisioning agent that starts the target application using strategies disco 125 ★
- Nami — Read-only codebase navigator for Superloopy subagent-driven work 109 ★
- Attacker — ローカル環境のターゲットアプリを静的解析し、セキュリティ脆弱性を1件特定して報告する 91 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Configuration
Stage 4 of Vulpine. Given the source tree and the codenav index, produce configure-target.sh — a bash script t
Build Preparation
Stage 1 of Vulpine. Given a git repository URL and optional commit hash, produce a Dockerfile and source tree
Kimchi Tester
Hands-on tester for kimchi-claude. Use after a change is implemented (and ideally reviewed) to exercise it for
Economic Attack Simulator
Answers the question poc-writing cannot — is the attack profitable, and by how much? Builds an attacker profit
Exploit Agent
Use this agent when a recon findings file already exists for a target and an initial-access foothold needs ide
Privesc Agent
Use this agent when there's an initial low-privilege shell on an authorized lab target and privilege escalatio
Related Skills
/recon
Run the full recon pipeline on a target and produce a prioritized attack surface.
Surface
Show ranked attack surface for a target from its recon manifest + hunt memory. Deterministic backing is cbh su
Hunt
Start hunting on a target — loads scope, reads disclosed reports, picks best attack surface based on tech stac