cain-agent

by cdxiaodongVerified

Real-world AI penetration testing engineer for authorized assessments — built-in cloud module covering AWS/Azure/GCP + Aliyun/Tencent/Huawei clouds. Built on Claude Agent SDK

322
Stars
74
Forks
Python
Language
8/23/2026
Added
View on GitHubDownload ZIP

⚠️ Third-Party Software Notice

This skill is third-party open-source software developed and hosted independently on GitHub. SkillTip is an informational directory and does not control or maintain the underlying repository. Any security checks displayed are automated and limited in scope. Review the source code before installing.

Read the Terms of Service

Installation

Add to your Claude Code skills directory:

# Add to your Claude Code skills
git clone https://github.com/cdxiaodong/cain-agent

Getting Started

Guides for using skills like cain-agent.

Security Report

Verified

Last scanned: —

{
  "status": "PASSED",
  "issues": []
}

README.md

Cain — Real-world AI Penetration Testing Engineer

Cain is an AI penetration-testing engineer built for real-world authorized security assessments — not a CTF toy. It walks a deterministic attack pipeline, enforces scope with engineering constraints (not AI self-discipline), and ships a cloud penetration module covering AWS / Azure / GCP / 阿里云 / 腾讯云 / 华为云 — including the Chinese clouds nobody else covers.

🚧 Actively developed. Star & watch for updates.

Built on the Claude Agent SDK.


Why Cain

CTF/靶场型 AgentCain (实战型)
TargetStatic labs, preset flagsReal enterprise assets, bug bounty, authorized engagements
Vulnerability focusKnown syntax-pattern vulnsBusiness-logic flaws, auth chains, cloud misconfigurations
EnvironmentNo WAF, no rate limitingReal WAF / risk control with dynamic strategy adjustment
DeliverableA flagAuditable evidence chain + reproducible PoC + remediation advice

Features

  • 🎯 Real-world Focus: Business-logic flaws, auth chains, cloud misconfigurations
  • ☁️ Cloud Native: AWS / Azure / GCP / 阿里云 / 腾讯云 / 华为云 coverage
  • 🔒 Safety First: Read-only by default, scope enforcement, credential redaction
  • 🤖 AI-Powered: Claude Agent SDK with deterministic orchestration
  • 📊 Benchmark: self-built vulnerable-terraform evaluation, four-metric scoring
  • 🛡️ OWASP Top 10: SQLi, XSS, SSRF, CSRF, File Upload, XXE, Command Injection, Path Traversal

Quick Start

git clone https://github.com/cdxiaodong/cain-agent
cd cain-agent
pip install -e .          # or: uv pip install -e .

cain-agent --version

For AI Agents — One-Click Install Prompt

"安装 cain-agent 到用户本地 Python 环境,克隆仓库 https://github.com/cdxiaodong/cain-agent,用 pip/uv 装 editable 模式,验证 CLI 可执行"

This single prompt instructs any AI agent to:

  1. Clone the repository
  2. Install in editable mode (pip install -e . or uv pip install -e .)
  3. Verify installation by running cain-agent --version

Run against a target

The target is written into scope.yaml and enforced on every tool call:

cain-agent run \
  --target https://app.example.com \
  --total-budget 1800

Flags: --target (required) · --workspace (state dir, default ./workspace) · --total-budget (wall-clock seconds) · --idle-timeout (per-step seconds)


Architecture

Deterministic engineering constrains agent freedom — stage transitions, scope enforcement and dangerous-operation circuit breakers are hard constraints; path selection and evidence analysis are left to the agent.

                    ┌──────────────────────────────────────────────┐
                    │                 Cain CLI                     │
                    │   cain-agent run --target <t> [--dry-run]    │
                    └───────────────────┬──────────────────────────┘
                                        │
                            ┌───────────▼───────────┐
                            │    Scope Bootstrap     │  target → scope.yaml
                            └───────────┬───────────┘
                                        │
                            ┌───────────▼───────────┐
                            │      Orchestrator      │  deterministic state machine
                            │  recon → test → report │  crash-resumable · scoped
                            └──┬────────┬────────┬──┘
                               │        │        │
              ┌────────────────▼┐   ┌───▼────┐  ┌▼──────────────┐
              │  Recon  Handler │   │  Test  │  │    Report      │
              │  (skill-guided) │   │Handler │  │   Handler      │
              └────────┬────────┘   └───┬────┘  └───────┬────────┘
                       │                │                │
                       └────────┬───────┴───────┬────────┘
                                │               │
                    ┌───────────▼──────┐   ┌────▼───────────────┐
                    │   SDK Executor    │   │  Findings Pipeline  │
                    │ (Planner/Executor)│   │ finder → validator  │  distinct sessions
                    │  allowed_tools=[] │   │ (never shared)      │
                    └─────────┬─────────┘   └─────────────────────┘
                              │
        ┌─────────────────────┼──────────────────────┐
        │                     │                      │
┌───────▼────────┐  ┌─────────▼─────────┐  ┌─────────▼────────┐
│  PreToolUse     │  │   Readonly Guard   │  │   Cloud Module    │
│  Scope Guard    │  │  46 read-only      │  │  IAM privesc ·    │
│  + Cred redact  │  │  security tools    │  │  storage · SSRF   │
└─────────────────┘  └────────────────────┘  └──────────────────┘

All state lives as files in the Workspace (external memory) —
crash-resumable and auditable end-to-end.

Safety is structural, not behavioral:

  • Scope enforcement — a PreToolUse hook blocks any tool call whose target falls outside scope.yaml; scope is enforced by configuration, not by the model's good behavior.
  • Read-only toolchain — 46 built-in security tools (recon / scan / verify / post / report), each with a per-tool dangerous_flags blacklist; write/exploit/persist operations (POST, PUT, DELETE, aws rm/mv/cp, …) are rejected before execution.
  • Finder ≠ Validator — discovery and validation run in separate agent sessions that never share context, so a finding can't be self-confirmed. Verdicts are 4-state structured output.
  • Credential redaction — a redaction hook strips secrets before anything is persisted.

Cloud Module — the part nobody else does

aws_s3 · azure_blob · gcp_gcs · aliyun_oss · tencent_cos · huawei_obs   →  storage exposure
aws IAM · tencent_cam · aliyun_ram                                        →  privilege-escalation path analysis
k8s_rbac · docker_image                                                 →  cluster & image posture
cloud metadata SSRF (IMDS / 169.254.169.254 across 7 providers)

IAM / RAM privilege-escalation graph — models entities → escalation actions → high-privilege targets as a directed graph, exports DOT / JSON for rendering, and finds escalation paths via BFS. Driven by the existing aliyun_ram / tencent_cam rule sets.

Benchmark — prove it, don't claim it

  • Self-built vulnerable-terraform range (bench/aliyun-vuln-tf/) with per-scene expected-detection fixtures.
  • Benchmark executor (bench/run_benchmark.py) scores each scene against four metrics: detection rate, false-positive rate, wall time, token cost — no hallucinated percentages; untested results are marked untested.
  • 44 test files covering the cloud modules, skills, pipeline and CLI.

⚠️ Legal & Ethical Use

Cain is strictly for authorized security testing — your own environments or engagements with written authorization. Core features run with read-only credentials; scope is enforced by configuration, not by AI self-discipline. You are responsible for complying with applicable laws.

Status

Core MVP is functional — deterministic pipeline, safety hooks, cloud module and benchmark are in place. See ROADMAP.md for what's next and CHANGELOG.md for recent work.

License

Apache-2.0. See LICENSE.

Frequently Asked Questions

What is cain-agent?

cain-agent is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by cdxiaodong. Real-world AI penetration testing engineer for authorized assessments — built-in cloud module covering AWS/Azure/GCP + Aliyun/Tencent/Huawei clouds. Built on Claude Agent SDK. It has 322 GitHub stars.

Is cain-agent safe to use?

Yes. cain-agent passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.

How do I install cain-agent?

Clone the repository with "git clone https://github.com/cdxiaodong/cain-agent" and add it to your Claude Code skills directory (see the Installation section above).

What programming language is cain-agent written in?

cain-agent is primarily written in Python. It is open-source under cdxiaodong on GitHub, so you can review or fork the full source.

Are there alternatives to cain-agent?

Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh cain-agent against similar tools.

Comments (0)

No comments yet. Be the first to share your thoughts!

ECC

by affaan-m

10

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

242,21936,702JavaScript
AI Agentsai-agentsanthropicclaude-code
View details
15

An agentic skills framework & software development methodology that works.

234,96620,863Shell
AI Agentsai-agentsbrainstorming
View details

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

185,94028,768JavaScript
AI Agentsai-agentsanthropicclaude-code
View details

cc-switch

by farion1231

3

A cross-platform desktop All-in-One assistant for Claude Code, Codex, OpenCode, OpenClaw, Grok Build & Hermes Agent. Only official website: ccswitch.io

128,8688,826Rust
AI Agentsclaude-codeai-tools
View details

claude-code

by anthropics

Claude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster by executing routine tasks, explaining complex code, and handling git workflows - all through natural language commands.

120,03119,897Shell
AI Agents
View details

Developers Also Liked

Based on votes and bookmarks from developers who liked this skill

ECC

by affaan-m

10

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

242,21936,702JavaScript
AI Agentsai-agentsanthropicclaude-code
View details
15

An agentic skills framework & software development methodology that works.

234,96620,863Shell
AI Agentsai-agentsbrainstorming
View details

n8n

by n8n-io

12

Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.

201,88160,308TypeScript
MCP Serversapisai-tools
View details

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

185,94028,768JavaScript
AI Agentsai-agentsanthropicclaude-code
View details

cc-switch

by farion1231

3

A cross-platform desktop All-in-One assistant for Claude Code, Codex, OpenCode, OpenClaw, Grok Build & Hermes Agent. Only official website: ccswitch.io

128,8688,826Rust
AI Agentsclaude-codeai-tools
View details