attack-surface-mapper

Maintain a living inventory of deployed systems and exposure details.

Updated Jun 30, 2026
One-click install
npx skills add https://github.com/Festo-Wampamba/Claude-Features --skill attack-surface-mapper
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: attack-surface-mapper
Source: https://github.com/Festo-Wampamba/Claude-Features/tree/main/skills/attack-surface-mapper
Command: npx skills add https://github.com/Festo-Wampamba/Claude-Features --skill attack-surface-mapper

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Keeps a living inventory of deployed systems and helps assess how exposed a single service is, so security posture does not depend on memory or scattered notes.

Core Features & Use Cases

  • Maintain Mode: Builds and updates attacksurface.md with systems, tech stack, hosting, auth, exposure, data sensitivity, defenses, known risks, and cadence.
  • Assess Mode: Performs a deep-dive on one named system, confirming current state, enumerating surface area, checking platform-specific misconfigurations, and reporting ranked findings with fixes.
  • Use Case: Use it when you need to answer what is deployed where, or when you want a focused security review of one app, API, database, or site.

Quick Start

Ask the skill to update your attack surface inventory from your project files and connected deployment sources, or to assess one named system for exposure and misconfiguration risk.

Frequently Asked Questions about attack-surface-mapper

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I maintain an attack surface inventory across multiple deployed systems?

Maintaining an attack surface inventory requires tracking deployed systems, hosting, and exposure details. This skill builds a living record by discovering data from local project files and connected deployment tools, ensuring your security posture relies on documented facts rather than scattered notes.

What is involved in assessing the exposure of a single hosted service?

Assessing the exposure of a single hosted service involves enumerating its surface area and checking for platform-specific misconfigurations. The skill performs a deep-dive on a named system to confirm its current state, reporting ranked findings with recommended fixes based on identified risks.

Can I use this to track security risks for multi-project environments without manual entry?

Yes, you can track security risks for multi-project environments without relying solely on manual entry. The skill requires discovery from connected deployment tools and local project files to automatically record technology stack, hosting, and authentication details for your deployed systems.

How do I check platform-specific misconfigurations for my deployed APIs and databases?

To check platform-specific misconfigurations for deployed APIs and databases, you initiate an assessment on the named system. The skill enumerates the surface area and evaluates current defenses and data sensitivity to report ranked findings and actionable fixes.

What details do I need to provide to review the attack surface of a specific domain or vendor?

To review the attack surface of a specific domain or vendor, you need to provide direct user input about the named service. The skill uses this input alongside local project files to record technology stack, exposure, defenses, and known risks for your assessment.