POC Builder — Security agent for Claude Code
Build a minimal proof of concept for a confirmed security finding.
How to install POC Builder
Installs to ~/.claude/agents/wrxck-auto-audit-poc-builder.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/wrxck/auto-audit/HEAD/agents/poc-builder.md -o ~/.claude/agents/wrxck-auto-audit-poc-builder.md Restart Claude Code, or start a new session, for it to be picked up.
What POC Builder does
name: poc-builder description: "Build a minimal proof of concept for a confirmed security finding. Writes a failing test, a small script, or a written exploit trace that demonstrates the vulnerability. Does NOT modify source code. Invoke this when a finding is in the `confirmed` state." tools: "Bash Read Write Grep Glob" model: "claude-sonnet-4-6"
You are a security researcher writing a **proof of concept**. Your output demonstrates the vulnerability is real, reproducible, and understoo
Alternatives in Security
- Audit Verifier — Adversarially verifies one candidate finding from /bug-audit — tries to REFUTE it by reading the code and, whe 335 ★
- Security Verifier — You write and execute PoC tests to PROVE bugs exist 215 ★
- After Confirming A Vulnerability — findings.sh update vuln --status confirmed --confirmed-by "poc-validator" \ --poc-output " " findings.sh updat 213 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Security Fixer
Implement the minimal fix for a confirmed security finding with a working PoC. Creates a branch, edits source
POC Engineer
Given a confirmed finding + its context worksheet, produces the smallest self-contained crate that reproduces
Vuln Patcher
Writes minimal, verified fix patches for confirmed vulnerabilities as diff files under reports/, without modif
Vuln Discloser
Re-verifies confirmed findings against the latest upstream release and drafts maintainer-ready security adviso
Finding Chain Synthesizer
Chains confirmed audit findings into multi-step, cross-domain exploit candidates and searches for a unique eme
Finding Reporter
Phase 14 per-finding report authoring agent. Reads a single finding directory (draft.md, debate.md, adversaria
Related Skills
POC
Generate an executable proof-of-concept exploit for a confirmed High/Critical finding — detect the toolchain,
Zp Cve
Known-CVE check - version fingerprint to confirmed finding, backed by KEV and the local exploit corpora. Usage
Build POC
Build a Proof of Concept (PoC) to validate technical feasibility and retire architectural risks