Skip to content
Back to skills

Cmd Mindmap

ASecurity

Generate a text-based attack surface mindmap. Shows tech stack → vuln class → endpoint relationships. Usage: /mindmap <target>

  • 815 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added May 29, 2026
ai-agentspythonrustgosqlnextjsnodeapici/cd

Works with

  • api

Security analysis

A100/100

Scanned May 29, 2026

npx -y skills add H-mmer/pentest-agents --skill mindmap --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cmd Mindmap?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cmd Mindmap
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/h-mmer-cmd-mindmap/badge)](https://www.skillsdirectory.com/skills/h-mmer-cmd-mindmap)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: mindmap
description: "Generate a text-based attack surface mindmap. Shows tech stack → vuln class → endpoint relationships. Usage: /mindmap <target>"
---

Generate attack surface mindmap for: $ARGUMENTS

## Process
1. Read brain data: `uv run python3 ../../tools/brain.py brief $ARGUMENTS`
2. Read recon data from recon/ directory
3. Read intel data: `uv run python3 ../../tools/intel_engine.py suggest <tech-stack>`
4. Generate a tree-format mindmap:

```
target.com
├── Tech Stack
│   ├── Next.js 14 → SSRF (Server Actions), Open Redirect
│   ├── GraphQL → Introspection, IDOR via node(), Mutation Auth
│   └── PostgreSQL → SQL Injection
├── Auth
│   ├── Okta SSO → SAML bypass, OAuth redirect_uri
│   └── JWT → Secret brute-force, Algorithm confusion
├── API Surface
│   ├── /api/v2/users/{id}/* → IDOR (P1)
│   │   ├── /orders — TESTED: exhausted
│   │   ├── /export — UNTESTED
│   │   └── /settings — UNTESTED
│   ├── /api/v2/payments/* → Race conditions, price manipulation (P1)
│   └── /graphql → Auth bypass on mutations (P1)
├── File Handling
│   └── /upload → Extension bypass, SVG XSS (P2)
└── Findings
    ├── [CONFIRMED] IDOR on /api/v2/users/{id}/orders
    └── [EXHAUSTED] XSS on /search — CloudFront blocks all payloads
```

5. Mark each endpoint as TESTED, UNTESTED, CONFIRMED, or EXHAUSTED from brain data
6. Suggest: "Start with UNTESTED P1 endpoints. Run /hunt $ARGUMENTS --vuln-class <suggested>"

## Top-Tier Mindmap Standard

The mindmap should expose attack decisions at a glance.

- Group by trust boundary first: unauth, user, tenant, admin, integration, internal, CI/CD, AI/tool.
- Mark every node with one of: `P1`, `P2`, `Kill`, `Confirmed`, `Partial`, `Exhausted`, `Chain`.
- Draw capability edges, not just URL hierarchy: export reads data, webhook sends server-side request, template renders attacker input, OAuth callback grants token.
- Surface blind spots explicitly: "no second-account test", "no browser verification", "no sibling replay", "no chain attempt".
- End with the top three routes where one more test could change severity or reportability.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…