attack-surface-mapping
Installation
SKILL.md
Attack Surface Mapping
Given one target and one application, draw the surface from what that application already exposes. Then stop. Testing lives in other skills.
This skill is the fast path. Success is a portrait plus a host/API inventory plus a key table plus response-class labels plus an object graph. A probe count is not success.
Field patterns for where the rest of the surface actually lives: SURFACE_PATTERNS.md.
When
- A new URL, a new app, or "I only see a login page"
- Need to know what to test before loading injection / auth / upload skills
- The agent is about to brute directories, spray quotes, or expand to unrelated hosts
Do not use this skill to expand an organization-wide host universe. Map the current application cluster. Finish it. Then, if scope allows, take the next cluster.
Authorization and destruction bounds: hack start gate. Stay in scope.