vuln-search-technique
Installation
SKILL.md
Vuln-search technique
Goal: convert a recon-produced asset inventory into a confirmed, prioritized, exploitable vulnerability list ready for vuln-exploit-technique or web-exploit-technique.
When this technique applies
- Recon is complete: asset inventory, open ports, service versions, web tech known.
- Need systematic vulnerability discovery before attempting exploitation.
- Scope requires coverage (audit, pentest) — not opportunistic attack.
- Target includes web applications, APIs, or services requiring deeper manual analysis.
Boundary
- Input from
recon-technique: asset list, port/service/version inventory, web fingerprint. - Output to
vuln-exploit-technique: confirmed infrastructure/service vulnerabilities with CVE, severity, exploitation path. - Output to
web-exploit-technique: confirmed web app vulnerabilities (SQLi, SSRF, auth bypass, etc.) with class, surface, and exploitation route. - Not covered: exploitation — this skill stops at confirmed finding + exploitation route.
- Fuzzing: deep campaigns follow
fuzzing-technique; integrated here as a bounded probe phase.