By clouditera
Automatically reproduces vulnerabilities from Markdown reports on target URLs, Docker Compose setups, or code paths using AI-orchestrated agents. Sets up real/mock environments, performs two-round pentesting with Playwright browser automation and API requests, strictly validates evidence like screenshots/HTTP logs/RCE outputs, and generates PoC scripts plus standardized reports.
npx claudepluginhub Clouditera/AI-Vuln-Reproduce --plugin vuln-reproduce> **历史文档说明**:本文档中提到的 `rce-success-criteria.md` 已合并到 `vuln-success-criteria.md`。
API 复现器,通过 HTTP 请求直接验证 API 层漏洞
环境专家,搭建测试环境并准备凭据和数据
Mock 环境准备器,独立准备隔离测试环境(只准备环境,不执行测试)
渗透测试员,使用 L1/L2 执行漏洞复现并收集证据(v2.0 架构)
QA 验证员,验证复现结果并判定状态(v2.0 架构)
报告撰写者,生成标准化复现报告和汇总报告
复现编排器,协调各角色完成漏洞复现(v2.0 两轮复现架构)
> vuln-reproduce 插件的规则文件索引和使用指南
> **Owner**: 分析师 (vuln-analyst)
> **Owner**: 编排器 (reproduce-orchestrator)
> **Owner**: QA 验证员 (qa-validator)
> **Owner**: 分析师 (vuln-analyst)
> **Owner**: 分析师 (vuln-analyst)
> **Owner**: 分析师 (vuln-analyst)
> **Owner**: 验证 (api-reproducer)
> **Owner**: 编排器 (reproduce-orchestrator)
> **Owner**: QA 验证员 (qa-validator)
> **Owner**: QA 验证员 (qa-validator)
> **Owner**: 报告撰写者 (report-writer)
> **Owner**: 验证 (api-reproducer)
> **Owner**: 分析师 (vuln-analyst)
> **Owner**: 编排器 (reproduce-orchestrator)
> **Owner**: 环境专家 (env-engineer)
> **Owner**: QA 验证员 (qa-validator)
漏洞分析师,阅读漏洞报告并制定复现方案
Uses power tools
Uses Bash, Write, or Edit tools
Complete collection of battle-tested Claude Code configs from an Anthropic hackathon winner - agents, skills, hooks, rules, and legacy command shims evolved over 10+ months of intensive daily use
Comprehensive .NET development skills for modern C#, ASP.NET, MAUI, Blazor, Aspire, EF Core, Native AOT, testing, security, performance optimization, CI/CD, and cloud-native applications
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
Tools to maintain and improve CLAUDE.md files - audit quality, capture session learnings, and keep project memory current.
Core skills library for Claude Code: TDD, debugging, collaboration patterns, and proven techniques
Team-oriented workflow plugin with role agents, 27 specialist agents, ECC-inspired commands, layered rules, and hooks skeleton.