full-attack-chain

Automate end-to-end penetration testing workflows from recon to post-exploitation reporting.

7|Updated Feb 11, 2026
One-click install
npx skills add https://github.com/valITino/blhackbox --skill full-attack-chain
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: full-attack-chain
Source: https://github.com/valITino/blhackbox/tree/main/.claude/skills/full-attack-chain
Command: npx skills add https://github.com/valITino/blhackbox --skill full-attack-chain

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Automates end-to-end penetration testing workflows from recon to reporting, enabling authorized teams to perform comprehensive attack chain assessments with consistent evidence and structured results.

Core Features & Use Cases

  • Comprehensive attack chain execution: recon, scanning, exploitation, data extraction, post-exploitation, and reporting.
  • Interactive target configuration and engagement scope: define domain, IP, in-scope assets, and permissions to guide the assessment.
  • Evidence generation and storytelling: PoCs, logs, screenshots, and an evidence index for traceability.
  • Attack chain construction: document chains with step-by-step evidence, tools used, data extracted at each step, and demonstrated impact.
  • Data aggregation and comprehensive reporting: mandatory data aggregation via get_payload_schema and aggregate_results, followed by a full professional report.

Quick Start

Provide the target domain or IP and engagement scope to initiate the full attack chain assessment.

Frequently Asked Questions about full-attack-chain

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate an end-to-end penetration testing workflow from recon to reporting?

Automating an end-to-end penetration testing workflow involves executing recon, scanning, exploitation, data extraction, and post-exploitation. This Skill structures the entire attack chain to generate consistent evidence and comprehensive professional reports for authorized security assessments.

What is included in post-exploitation reporting for an attack chain assessment?

Post-exploitation reporting includes mandatory PoCs, logs, screenshots, and an evidence index for traceability. It documents step-by-step attack chains, tools used, data extracted at each step, demonstrated impact, and compliance fields required for engagement documentation.

How do I configure target scope and permissions before starting a pentest?

You configure target scope by defining the domain, IP, in-scope assets, and permissions during interactive engagement setup. This target configuration guides the automated assessment, ensuring the attack chain operates strictly within authorized security assessment boundaries.

Can I use this attack chain automation for complex environments in authorized security assessments?

Yes, this attack chain automation is designed for authorized security assessments of complex environments. It applies structured outputs, safety checks, and mandatory data aggregation to handle comprehensive penetration testing workflows while maintaining compliance.

How are penetration testing payloads and evidence aggregated for final documentation?

Payloads and evidence are aggregated using mandatory data aggregation via get_payload_schema and aggregate_results. This process indexes evidence, consolidates extracted data, and produces structured outputs that feed directly into the final engagement documentation and comprehensive report.

What are the limitations of automating penetration testing workflows?

Automating penetration testing workflows requires strict adherence to authorized engagement scope and permissions. Safety checks and compliance fields are mandatory, meaning the automation should not be used outside explicitly defined, authorized security assessment boundaries.