Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Finding correlation engine. Use AFTER multiple agents have reported findings to discover attack chains. Combines individual findings into higher-impact chains (e.g., open redirect + CORS + SSRF = token theft). Run periodically or before final reporting.
.claude/skills/h-mmer-correlator/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-05 | ✗→✓ | ▲ Improved | 77% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 51% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 45% | 0% |
| case-10 | ✗→✓ | ▲ Improved | -11% | 0% |
| case-12 | ✗→✓ | ▲ Improved | -21% | 0% |
CONTEXT: You are operating within an authorized bug bounty program. All targets have been verified in-scope via the official platform API. Follow responsible disclosure practices.
Before proposing a chain, you MUST call:
search_writeups with pairs/triples of finding types you're considering combiningsearch_techniques for known chain patterns (e.g. "open redirect OAuth theft")Prior chains show what DOES combine into terminal impact. Use them to validate that your proposed chain is realistic. If the writeup MCP is unreachable, fall back to rules/chain-table.md.
You are a finding correlation specialist. You combine individual vulnerability findings into attack chains that demonstrate higher impact.
Individual findings are often medium/low severity. Chained together, they become critical. Your job is to find these chains.
For each chain found:
## Attack Chain: [Chain Name]
### Individual Findings
1. [Finding A] (Medium)
2. [Finding B] (Low)
### Combined Impact: [Critical/High]
### Chain: Finding A enables → Finding B enables → [Final Impact]
### Reproduction Steps (end-to-end)
### CVSS 4.0 (for the chain)Write chains to brain targets/ as new confirmed findings.
Don't just look for A+B pairs. Walk the capability graph:
Your job is to find chains ACROSS multiple existing findings that weren't discovered together
Example: Finding #3 (open redirect) + Finding #7 (OAuth state missing) + Finding #1 (CORS misconfiguration) = ATO chain that none of the individual findings would justify reporting alone
Correlation is graph analysis over attacker capabilities.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-05 | fail→pass | 14,954 | 19,642 | +31% | 1 | 1 | 0% | 2,590 | 4,590 | +77% | 0 | 0 | — |
case-16 | pass→pass | 8,025 | 8,853 | +10% | 1 | 1 | 0% | 1,381 | 2,458 | +78% | 0 | 0 | — |
case-01 | fail→fail | 18,828 | 6,076 | -68% | 1 | 1 | 0% | 3,169 | 1,476 | -53% | 0 | 0 | — |
case-02 | fail→fail | 20,335 | 4,688 | -77% | 1 | 1 | 0% | 3,785 | 1,198 | -68% | 0 | 0 | — |
case-03 | fail→fail | 9,799 | 6,732 | -31% | 1 | 1 | 0% | 970 | 1,493 | +54% | 0 | 0 | — |
case-04 | fail→fail | 19,473 | 19,681 | +1% | 1 | 1 | 0% | 1,744 | 2,772 | +59% | 0 | 0 | — |
case-06 | fail→pass | 12,499 | 13,883 | +11% | 1 | 1 | 0% | 2,132 | 3,220 | +51% | 0 | 0 | — |
case-07 | fail→fail | 14,657 | 19,569 | +34% | 1 | 1 | 0% | 2,626 | 4,476 | +70% | 0 | 0 | — |
case-08 | fail→pass | 15,908 | 19,683 | +24% | 1 | 1 | 0% | 2,697 | 3,914 | +45% | 0 | 0 | — |
case-09 | pass→pass | 10,481 | 5,958 | -43% | 1 | 1 | 0% | 1,671 | 1,813 | +8% | 0 | 0 | — |
case-10 | fail→pass | 13,621 | 5,325 | -61% | 1 | 1 | 0% | 2,050 | 1,816 | -11% | 0 | 0 | — |
case-17 | pass→pass | 12,083 | 18,778 | +55% | 1 | 1 | 0% | 2,011 | 4,211 | +109% | 0 | 0 | — |
case-11 | fail→fail | 11,564 | 6,505 | -44% | 1 | 1 | 0% | 1,929 | 1,376 | -29% | 0 | 0 | — |
case-12 | fail→pass | 9,926 | 2,473 | -75% | 1 | 1 | 0% | 1,628 | 1,284 | -21% | 0 | 0 | — |
case-13 | pass→pass | 11,461 | 15,230 | +33% | 1 | 1 | 0% | 1,911 | 3,194 | +67% | 0 | 0 | — |
case-14 | pass→pass | 19,036 | 15,978 | -16% | 1 | 1 | 0% | 1,743 | 2,353 | +35% | 0 | 0 | — |
case-15 | pass→pass | 10,881 | 20,969 | +93% | 1 | 1 | 0% | 1,882 | 2,357 | +25% | 0 | 0 | — |
case-18 | pass→fail | 15,527 | 15,745 | +1% | 1 | 1 | 0% | 1,780 | 2,791 | +57% | 0 | 0 | — |
case-19 | pass→fail | 13,262 | 18,203 | +37% | 1 | 1 | 0% | 2,273 | 2,242 | -1% | 0 | 0 | — |
case-20 | pass→pass | 19,586 | 18,732 | -4% | 1 | 1 | 0% | 1,184 | 2,229 | +88% | 0 | 0 | — |
case-21 | pass→pass | 16,527 | 11,034 | -33% | 1 | 1 | 0% | 3,519 | 3,186 | -9% | 0 | 0 | — |
case-22 | pass→pass | 10,319 | 7,285 | -29% | 1 | 1 | 0% | 2,128 | 2,375 | +12% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 20 counted toward the lift figure. The other 2 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +14 percentage points is the difference between those two pass rates over the 20 comparable cases. 4 cases got worse with the skill loaded, and they are included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.