Ext Attack Planner — Security agent for Claude Code
Reasons from an external-pentest inventory to the most likely footholds in an authorized engagement.
How to install Ext Attack Planner
Installs to ~/.claude/agents/xcoy0te-claude-externalpentest-ext-attack-planner.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/xcoy0te/Claude-ExternalPentest/HEAD/agents/ext-attack-planner.md -o ~/.claude/agents/xcoy0te-claude-externalpentest-ext-attack-planner.md Restart Claude Code, or start a new session, for it to be picked up.
What Ext Attack Planner does
name: ext-attack-planner description: Reasons from an external-pentest inventory to the most likely footholds in an authorized engagement. Correlates services/versions/web findings/cloud exposure with known vulns, default creds, misconfigurations and takeovers, and presents a ranked, human-approved plan mapped to CVSS. It plans and explains; it never executes. model: sonnet allowed-tools: Bash, Read, Write, WebSearch, WebFetch
External Attack Planner
You reason about how an external
Alternatives in Security
- Token Auditor — Scans ui/src/ for hardcoded visual values, duplicate components, and shadcn replacement candidates; produces d 79.4k ★
- Anti Reversing Techniques — AUTHORIZED USE ONLY: This skill contains dual-use security techniques 31.9k ★
- Brain — Central knowledge coordinator 812 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Ext Exploit Operator
Executes ONE approved step from an external-pentest attack plan in an authorized engagement. Runs the specific
Services Planner
Plans required vendors and services such as music, decoration, photography, equipment rental, security, or tra
Pentest Commander
Pentest engagement lead. Owns research, planning, multi-domain grow-agent dispatch, cross-target synthesis, an
Pentest Validator
Optional, disabled-by-default Dynamic Security Validation agent. Interacts with a running, explicitly authoriz
Orbit Security
SAST, WP-specific vulns, CVE watching, escape/nonce/capability audits. Also: payment security (Stripe/Freemius
Aspm Correlator
Application Security Posture Management persona. Correlates findings from SAST, DAST, and SCA tools, deduplica
Related Skills
Ext Attack Paths
Launch the ext-attack-planner agent to reason from the enumerated exposures to likely footholds, then present
Find Programs
Scout publicly-listed HackerOne, Bugcrowd, or Intigriti bug-bounty programs likely to yield reportables on bot
Mingyi Atlas
Harness-driven terminal AI agent for authorized security assessment, with TUI, headless automation, persistent