attack-planner

attack-planner is an agent for coding agents from 0xSteph/pentest-ai-agents. It costs 54 tokens per session (2,139 once invoked), scanned A, original, MIT.

An attack-planning agent for authorized penetration tests that combines findings from many security tools into connected attack paths. A penetration test is an approved attempt to show how an environment could be compromised.

In plain words
What is it for?
It helps correlate network, web, cloud, directory, credential, vulnerability, and public-information findings, then prioritize possible routes and business impact.
Why use it?
It helps turn isolated findings into a clear explanation of how an attacker could reach important systems or data.

Agent

Part of the pentest-ai-agents plugin — 3 commands, 53 agents shipped together

About the project

0xSteph/pentest-ai-agents is a collection of Claude Code specialist agents for authorized penetration testing and security research, covering areas such as reconnaissance, web systems, cloud, reverse engineering and detection. Security researchers and penetration testers use it to plan engagements, investigate findings, build detections and write reports. The catalogue entries are the project's own agents, commands and plugin components.

0xSteph/pentest-ai-agents · 2,197 stars · on GitHub

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/0xsteph/pentest-ai-agents/attack-planner
Clone the repo
git clone --depth 1 https://github.com/0xSteph/pentest-ai-agents

Or install pentest-ai-agents, the plugin that ships this one along with the rest of its 3 commands, 53 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for attack-planner

README.md
[![agentmods](https://agentmods.dev/badge/agents/0xsteph/pentest-ai-agents/attack-planner.svg)](https://agentmods.dev/agents/0xsteph/pentest-ai-agents/attack-planner)
Your own site
<a href="https://agentmods.dev/agents/0xsteph/pentest-ai-agents/attack-planner"><img src="https://agentmods.dev/badge/agents/0xsteph/pentest-ai-agents/attack-planner.svg" alt="Measured on agentmods" height="20"></a>
Per session 54 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,139 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00054 $0.02139
Opus 5 $0.00027 $0.01069
Sonnet 5 $0.00011 $0.00428
Haiku 4.5 $0.00005 $0.00214

Measured 5d ago against content hash 5c160a5bfe7e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

attack-planner scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/attack-planner.md · 199 lines

How it starts

The opening of the file, as written. The whole thing — 199 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are an expert attack chain strategist for authorized penetration testing and red team engagements. You correlate findings from multiple reconnaissance, vulnerability scanning, and enumeration tools to build optimal multi-step attack paths through target environments.

You think like an advanced persistent threat (APT). You don't just find individual vulnerabilities; you chain them into complete attack narratives that demonstrate real business risk. You prioritize paths that maximize impact while minimizing detection.

Core Capabilities

Attack Chain Construction

You build end-to-end attack paths by correlating:

  • Reconnaissance data (Nmap, masscan, Shodan results)
  • Vulnerability scan findings (Nuclei, Nessus, OpenVAS, Nikto)
  • Web application testing results (SQL injection, XSS, SSRF findings)
  • Active Directory enumeration (BloodHound, CrackMapExec, ldapsearch)
  • Cloud enumeration (IAM policies, service configurations)
  • Credential test results (spraying results, cracked hashes)
  • OSINT findings (exposed credentials, leaked data, employee information)

Chain Link Types

Every attack chain is a sequence of these link types:

  1. Initial Access : How you get in (phishing, public exploit, default creds, VPN creds)
  2. Execution : How you run code (web shell, command injection, macro, script)
  3. Persistence : How you stay in (scheduled task, service, registry, cron)
  4. Privilege Escalation : How you go up (kernel exploit, misconfig, token impersonation)
  5. Defense Evasion : How you avoid detection (living off the land, log clearing, timestomping)
  6. Credential Access : How you get more creds (Mimikatz, Kerberoast, LSASS dump)
  7. Discovery : How you map the environment (AD enum, network scanning, file shares)
  8. Lateral Movement : How you move across (PSExec, WinRM, RDP, SSH, SMB)
  9. Collection : How you gather data (file access, database queries, email access)
  10. Exfiltration : How you get data out (HTTP, DNS, cloud storage)
  11. Impact : What business impact you demonstrate (domain admin, data access, ransomware simulation)

Read the full file on GitHub · 199 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 199 lines · 54 tokens per session scan A 5c160a5bfe7e

Subscribe to this mod's changes

attack-planner is an agent published in the GitHub repository 0xSteph/pentest-ai-agents (2,197 stars, last pushed 19d ago), licensed MIT. It adds 54 tokens to every session and 2,139 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

web3-auditor

Smart contract security auditor. Checks 10 bug classes in order of frequency (accounting desync 28%, access control 19%, incomplete path 17%, off-by-one 22% of Highs, oracle errors, ERC4626 attacks, reentrancy, flash loan oracle manipulation, signature replay, proxy/upgrade issues). Applies pre-dive kill signals…

Awarexone/Agentic-Bug-Hunter · 101 tokens

tachi-risk-scorer

Quantitative risk scoring agent that enriches threat model findings with four-dimensional scores (CVSS 3.1, exploitability, scalability, reachability), computes weighted composite scores, attaches governance fields, and generates dual-format output (risk-scores.md and risk-scores.sarif).

davidmatousek/tachi · 65 tokens

ux-ui-designer

UX/UI design, design systems, user flows, and accessibility compliance. Use for creating design specifications, component libraries, and WCAG-compliant interfaces.

davidmatousek/tachi · 35 tokens

web-researcher

Technical research, library evaluation, and best practices investigation. Use for comparing technologies, researching APIs, and finding documentation.

davidmatousek/tachi · 28 tokens

active-directory

Active Directory and Windows domain attack specialist. Use for Kerberoasting, AS-REP roasting, DCSync, BloodHound enumeration, ADCS ESC attacks, Golden/Silver Ticket, and domain privilege escalation. Triggers on: kerberoast, AS-REP, bloodhound, DCSync, golden ticket, ADCS, ESC, domain controller, LDAP, GPO, AD, domain…

mukul975/Threatswarm · 86 tokens

c2-operator

Command and control infrastructure specialist for authorized red team operations. Handles Sliver C2 framework, Havoc C2, Metasploit multi-handler, msfvenom payload generation, implant configuration, HTTPS C2 traffic blending, and operator session management. Triggers on: C2, command and control, Sliver, Havoc…

mukul975/Threatswarm · 94 tokens