---
name: Brain
slug: brain
category: Automation
description: Brain manages pentest engagement state with init, brief, status, exhausted, and record subcommands. Use it to capture targets, evidence, dead ends, and next actions during an assessment.
github: "https://github.com/H-mmer/pentest-agents/tree/main/.claude/skills/brain"
language: Python
stars: 804
forks: 156
install: "npx degit https://github.com/H-mmer/pentest-agents/tree/main/.claude/skills/brain ~/.claude/skills/brain"
installs_to: ~/.claude/skills/brain
source_path: .claude/skills/brain/SKILL.md
collection_size: 25
category_size: 1523
collection_url: "https://dirskills.com/collections/H-mmer/pentest-agents"
added: 2026-08-22T05:22:33.397Z
last_synced: 2026-08-22T05:22:33.397Z
canonical_url: "https://dirskills.com/skills/brain"
---

# Brain

Brain manages pentest engagement state with init, brief, status, exhausted, and record subcommands. Use it to capture targets, evidence, dead ends, and next actions during an assessment.

**Install:**

```bash
npx degit https://github.com/H-mmer/pentest-agents/tree/main/.claude/skills/brain ~/.claude/skills/brain
```

## README

Brain management: $ARGUMENTS

Route to the brain tool:
- If "$ARGUMENTS" is "init": run `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py init`
- If "$ARGUMENTS" starts with "brief": run `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py brief <target>`
- If "$ARGUMENTS" is "status": run `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py status`
- If "$ARGUMENTS" starts with "exhausted": run `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py exhausted <target>`
- If "$ARGUMENTS" starts with "record": run `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> <status> <technique> "<details>"`

After running, also launch the `brain` agent to update the MEMORY.md index if any state changed.

## Top-Tier Memory Bar

Bad memory makes the whole suite worse. Record facts as reusable evidence, not diary entries.

For every record, include:
- `target`: canonical host or repo name
- `surface`: endpoint, file, workflow, account role, or component
- `technique`: vuln class plus variant, not just "tested auth"
- `status`: confirmed, partial, exhausted, blocked, duplicate-risk, chain-pending
- `evidence`: request id, file path, response marker, screenshot path, command output, or blocker
- `next_action`: the exact command or test a future session should run

Never store "no bug" without the tested matrix. An exhausted entry must say what was tried and why that evidence is strong enough to skip it later.
