Agent skill

Attack Surface Mapping

by yaklang in yaklang/hack-skills

Draw a testable attack surface from one authorized target URL or one application.

MITAuto-check passedSecurity

Install Attack Surface Mapping

skills CLI
$ npx skills add yaklang/hack-skills --skill attack-surface-mapping -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yaklang/hack-skills attack-surface-mapping --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/attack-surface-mapping .claude/skills/attack-surface-mapping && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
attack-surface-mapping
GitHub stars
2.4k
Token cost
~2.6k tokens
SKILL.md length
1,278 words
Files
2
Skills in repo
26
Repo updated
First seen
Licence
MIT

At a glance

Draw a testable attack surface from one authorized target URL or one application.

  • Works in 7 steps: Portrait (mandatory, before any request… → Find the business plane → Inventory from the application → …
  • The user says 攻击面
  • SKILL.md covers When, What must exist (not a file…, Fast path and Handoff, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Attack Surface Mapping is an agent skill from yaklang/hack-skills. Draw a testable attack surface from one authorized target URL or one application. Use when the user says 攻击面, 供给面, 画攻击面, map the surface, application recon, find the business host, JS inventory, or when the only visible page is login. Derive hosts, APIs, keys, and the object graph from what the app already exposes. Do not open with directory brute or payload spray. Use when the user runs /attack-surface-mapping.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `SURFACE_PATTERNS.md`).

It sits in Security, covering Threat modeling. The repository describes itself as: Helping AI Agent become an awesome practical hacker! The licence is MIT.

When your agent uses it

  • The user says 攻击面
  • Map the surface
  • Application recon
  • Find the business host

Example prompts

  • “/attack-surface-mapping”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Portrait (mandatory, before any request spray)
  2. Find the business plane
  3. Inventory from the application
  4. Classify responses before any probe
  5. Object graph is surface
  6. Collapse same-skin and same-gate
  7. Surface-done (then hand off)

What it can do on your machine

Read from SKILL.md and the folder at commit 6fbf0bc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Attack Surface Mapping loads about 2.6k tokens when it runs. Until then it costs about 110 tokens; SKILL.md has 1,278 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~110
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yaklang/hack-skills at commit 6fbf0bc, republished under its MIT licence (© yaklang). 1,278 words, ~2,594 tokens.

Download SKILL.mdSave it as .claude/skills/attack-surface-mapping/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
attack-surface-mapping
description
Draw a testable attack surface from one authorized target URL or one application. Use when the user says 攻击面, 供给面, 画攻击面, map the surface, application recon, find the business host, JS inventory, or when the only visible page is login. Derive hosts, APIs, keys, and the object graph from what the app already exposes. Do not open with directory brute or payload spray. Use when the user runs /attack-surface-mapping.

Attack Surface Mapping

Given one target and one application, draw the surface from what that application already exposes. Then stop. Testing lives in other skills.

This skill is the fast path. Success is a portrait plus a host/API inventory plus a key table plus response-class labels plus an object graph. A probe count is not success.

Field patterns for where the rest of the surface actually lives: SURFACE_PATTERNS.md.

When

  • A new URL, a new app, or "I only see a login page"
  • Need to know what to test before loading injection / auth / upload skills
  • The agent is about to brute directories, spray quotes, or expand to unrelated hosts

Do not use this skill to expand an organization-wide host universe. Map the current application cluster. Finish it. Then, if scope allows, take the next cluster.

Authorization and destruction bounds: hack start gate. Stay in scope.

What must exist (not a file tree)

Before any vulnerability skill, these facts must be retrievable. Persist them in whatever the local workspace already uses for notes and evidence — an existing task folder, a proxy project, session notes, a ticket. Do not invent a new directory layout when one is already in play.

FactKeep
Portrait3–5 sentences, not an essay
HostsBusiness hosts, gateways, API domains this app already named
EndpointsMethod, path, params, auth required?
KeysSigning salt, ciphertext id + frontend pubkey, hidden/admin route, hardcoded demo account. Record none per row if absent
Response classLogin-gate / differential / unauthenticated exception
Object graphlist → detail → attachment / export / approval

Requests, diffs, and screenshots stay where they were captured when that store is already the working set. Empty inventory plus "I will brute paths next" is a failed mapping.

Fast path

Portrait
  → find the business plane (login is a shell)
  → inventory from the app (JS / traffic / docs), keys not just paths
  → classify responses
  → grow the object graph from responses
  → same-skin / same-gate collapse
  → surface-done → hand off

Do not insert directory brute, full-template scanning, or password spraying into this loop.

1. Portrait (mandatory, before any request spray)

Three to five sentences:

  • Who uses this (consumer / merchant / operator)
  • Core objects (order, ticket, coupon, document, tenant)
  • Which fields hold money, privilege, or state
  • What an unauthenticated caller can already touch

Cannot write it → capture one real page's traffic first. Do not scan into a blank portrait.

Mini-program, native app, GraphQL, WebSocket, batch export, agent-with-tools, template preview, file convert, command RPC: treat as this site's surface, not a sidenote.

2. Find the business plane

A login page is a shell. The surface is the post-login business host or the same-host gateway behind the form. Seeing a login page is not a reason to change assets.

Find the plane without logging in:

  • Query: service= / redirect_uri= / callback= / returnUrl= / jumpUrl= / next=
  • Client: env.js / baseURL / apiHost / /prod-api / VUE_APP_* / REACT_APP_*
  • Transport: 302 Location, X-Frame-Options: ALLOW-FROM
  • Naming: same-product api / admin / gateway / product host

Someone else's SSO / CAS / OAuth page: do not audit the identity product. Follow it back to this product's business plane. Criterion: the login page's owner is not this business.

Alive vs dead:

Treat as aliveTreat as dead
401, 403, login wall, admin challengeTimeout, parking page, no business response
Management console challengeDefault CDN / empty static shell with no script

Alive ≠ grind the form. Captcha OCR, slider farms, and login-box dictionaries are not mapping.

Form checks that are in-scope for mapping (once, then stop): empty password, skip-password step, extra fields on the login API (tenant / corpId / moduleId), business paths already visible next to the form (list / detail / stats). Username and password boxes are not business parameters.

3. Inventory from the application

Frontend present: open a business page → collect scripts (including async chunks and sourcemaps) → extract APIs and keys → capture traffic to fill gaps → persist endpoints and keys in the local evidence store.

JS extracts more than /api/ paths. For each row, write the value or none:

ExtractWhy it is surface
/api/ paths, RPC cmd numbers, GraphQL operationsEndpoint list
Signing salt, hardcoded key, sign that does not need a cookieReplay without a session
Ciphertext id + frontend public key (modulus / JSEncrypt)Neighbor-id is encryptable
Hidden / admin routes in the router, unpublished chunksAPIs the UI never shows
Hardcoded demo account, test tenant, experience entryA key, not a login-form dictionary
Command / template / expression / file-convert / RPC-with-exec / agent toolsExecution plane; do not invent params if none exist

No frontend / JS blocked: Swagger, OpenAPI, captured traffic, HTML inline, known gateway prefixes. Do not idle waiting for a full JS dump.

Frontend present but inventory empty → directory brute is forbidden.

Docs and debug planes, if this app already linked them: api-recon-and-docs. Exposed VCS / backups: insecure-source-code-management. Both are this cluster's extra planes, not a new search.

Show full SKILL.md (534 more words)Show less
4. Classify responses before any probe
ResponseClassMapping action
One sentence "please log in" / NotLogin, no list / total / roster / detailLogin gateDo not mark as an injection surface
Has list / total / business fields, even total=0DifferentialKeep on the test list
Error, 500, timeout, or length/timing off baselineDifferentialKeep; unstable diff → stop after one or two compares
Missing a parameter dumps a roster or detailUnauthenticated exceptionHighest-priority unauth surface

An empty list is "structure returned, count is 0", not a login gate.

5. Object graph is surface

Identifiers in any field name (id / userId / tenantId / fileKey / openid / ciphertext PK) are surface.

Walk, and write it down:

list → detail → attachment / export / preview / approval

Parent authorized, child often not. After a list passes, the next surface is the attachment, not a new host.

Anything a response newly names — id, download URL, token, internal host, role field — goes onto this site's queue immediately. Do not drop it when changing pages.

6. Collapse same-skin and same-gate

Fingerprint-same (title, skeleton, build hash, API prefix, login chain): pick 2–3 representatives. Siblings only get a glance: new path / new port / another app / another jump / service= / moduleId business plane. No new plane → do not open a full matrix.

Same-gate (all four):

  1. Business paths already extracted
  2. Unauthenticated exceptions already probed
  3. Remaining business endpoints return the same login-code family
  4. No unauthenticated other-subject data, and no missing-param dump

Then stop this gate. Siblings with the same baseURL + same code: glance for new paths or a code change. Auth endpoints (issue session / reset / rebind / ticket-swap) still go on the list if present; they are not "please log in, so skip".

Same host is not same-skin. Extra paths on the same host always expand.

No business script, default server page, or leftover behind the same login-code family: falsify once and leave. Do not pad with a full matrix.

7. Surface-done (then hand off)

Mapping is done when:

  1. Portrait exists, or this is recorded as a shell with no business object
  2. Endpoint inventory exists (full or degraded); keys have values or none — in the local evidence store, not a prescribed path
  3. Response classes labeled; unauthenticated exceptions ticked
  4. Object graph recorded, or recorded as unlistable
  5. Same-skin / same-gate leftovers glanced, not rematrixed
  6. Auth endpoints listed if the inventory has issue-session / reset / rebind / ticket-swap / 2FA — listed, not yet exploited

Then load hack for effort order and the matching category skill. Do not start testing inside this file.

Handoff

Surface you drewLoad
Unauthenticated other-subject data, object idsauth-sec, idor-broken-object-authorization
Issue-session / reset / rebind / ticket-swapauthbypass-authentication-flaws
Differential filters, URL-fetch params, templatesinjection-checking
Upload / preview / convertupload-insecure-files
Money / coupon / stock / approvalbusiness-logic-vuln
REST / GraphQL / gateway docsapi-sec
Public middleware adminunauthorized-access-common-services

Anti-patterns

  • Opening with directory brute or full-template scanning
  • Grinding captcha / default passwords on login HTML
  • Seeing a login page and changing assets
  • Script extracted only paths; salts, ciphertext ids, hidden routes, demo accounts unread
  • Treating 401 / 403 / login wall as dead
  • Pouring a full matrix into the same login-code family
  • Expanding to a new cluster while this application's live surface is unfinished
  • Calling mapping "done" because the homepage returned 200
  • Minting a new notes tree when the workspace or proxy project already holds the evidence

© yaklang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/attack-surface-mapping of yaklang/hack-skills.

  • SKILL.md
  • SURFACE_PATTERNS.md

Open the folder on GitHubat commit 6fbf0bc

Compare with similar skills

Attack Surface Mapping next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Attack Surface Mapping compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Attack Surface Mapping this skillyaklang/hack-skills2.4k—~2.6kAutomated safety check: PassMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
Create Rulecartography-cncf/cartography4.1k—~3kAutomated safety check: PassApache-2.0
Commit Security Scancodexstar69/bug-hunter519—~629Automated safety check: PassMIT
Auditing Code For Vulnerabilitiestrilwu/secskills156—~3.2kAutomated safety check: PassMIT

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • Create Rule

    cartography-cncf/cartography

    Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.

    4.1k GitHub stars~3k tokensUpdated today
    SecurityAuto-check passed
  • Commit Security Scan

    codexstar69/bug-hunter

    Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

    519 GitHub stars~629 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    156 GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.

    40k GitHub starsUsed in 8 repos~742 tokens
    SecurityAuto-check passed

More from yaklang/hack-skills

All 26 skills in this repo
  • Anti Debugging Techniques

    yaklang/hack-skills

    Anti-debugging detection and bypass playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~3.4k tokensUpdated 24 days ago
    Auto-check passed
  • API Auth And JWT Abuse

    yaklang/hack-skills

    API authentication and JWT abuse playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~567 tokensUpdated 24 days ago
    Auto-check passed
  • API Authorization And Bola

    yaklang/hack-skills

    API authorization and BOLA testing playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~449 tokensUpdated 24 days ago
    Auto-check passed
  • API Recon And Docs

    yaklang/hack-skills

    API reconnaissance and documentation review playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~456 tokensUpdated 24 days ago
    Auto-check passed
  • Classical Cipher Analysis

    yaklang/hack-skills

    Classical cipher analysis playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~4.8k tokensUpdated 24 days ago
    Auto-check passed
  • Code obfuscation analysis and deobfuscation playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~3.3k tokensUpdated 24 days ago
    Auto-check passed

Categories

Questions about Attack Surface Mapping

What does Attack Surface Mapping do?

Draw a testable attack surface from one authorized target URL or one application. Attack Surface Mapping is an agent skill from yaklang/hack-skills. Draw a testable attack surface from one authorized target URL or one application.

When should I use Attack Surface Mapping?

Attack Surface Mapping fits situations like: the user says 攻击面; map the surface; application recon; find the business host.

How do I install Attack Surface Mapping in Claude Code?

Run `npx skills add yaklang/hack-skills --skill attack-surface-mapping -a claude-code`. Or copy the skill folder (skills/attack-surface-mapping in yaklang/hack-skills) into .claude/skills/attack-surface-mapping in your project. Claude Code loads it when a task matches its description.

How do I install Attack Surface Mapping in Codex?

Run `npx skills add yaklang/hack-skills --skill attack-surface-mapping -a codex`. Or copy the skill folder (skills/attack-surface-mapping in yaklang/hack-skills) into .agents/skills/attack-surface-mapping in your project. Codex loads it when a task matches its description.

Can I use Attack Surface Mapping in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaklang/hack-skills --skill attack-surface-mapping -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/attack-surface-mapping, .gemini/skills/attack-surface-mapping, .github/skills/attack-surface-mapping and .opencode/skills/attack-surface-mapping in your project.

What does Attack Surface Mapping need to run?

SKILL.md names no scripts, command-line tools or credentials: Attack Surface Mapping is instructions for the agent only.

Does Attack Surface Mapping access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Attack Surface Mapping safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Attack Surface Mapping use?

Attack Surface Mapping is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Attack Surface Mapping use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Attack Surface Mapping?

Skills that share tags, products or a category with Attack Surface Mapping: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Forensify (alexgreensh/repo-forensics, 188 stars), Create Rule (cartography-cncf/cartography, 4.1k stars) and Commit Security Scan (codexstar69/bug-hunter, 519 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Attack Surface Mapping?

yaklang (a GitHub organization) maintains it in yaklang/hack-skills, which has 2,394 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on September 13, 2026.

Source: yaklang/hack-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.