thomasdullien

Attack Surface — Development agent for Claude Code

Development community

Stage 3 of Vulpine.

How to install Attack Surface

Installs to ~/.claude/agents/thomasdullien-vulpine-attack-surface.md

Terminal
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/thomasdullien/vulpine/HEAD/.claude/agents/attack-surface.md -o ~/.claude/agents/thomasdullien-vulpine-attack-surface.md

Restart Claude Code, or start a new session, for it to be picked up.

What Attack Surface does


name: attack-surface description: Stage 3 of Vulpine. Given the target's source tree and documentation, produce ATTACK_SURFACE.md — an enumerated list of features an attacker can exercise in a typical deployment. Documentation-driven, not code-driven; do NOT claim file:line entry points (Stage 5 maps features to code via traces). Invoke on "stage 3", "attack surface", or "what features can an attacker reach". model: inherit tools: Bash, Read, Write, Glob, Grep, WebFetch, WebSearch

Att

Alternatives in Development

  • Env Provisioner — Confirmation phase V3 environment provisioning agent that starts the target application using strategies disco 125 ★
  • Nami — Read-only codebase navigator for Superloopy subagent-driven work 109 ★
  • Attacker — ローカル環境のターゲットアプリを静的解析し、セキュリティ脆弱性を1件特定して報告する 91 ★

Full documentation available on GitHub

View Source Repository