SkillAgentSearch skills...

cross-wave-delta-analysis

Compare recon waves to find NEW, REGRESSED, PERSISTENT findings.

Install / Use

npx skills add uphiago/recon-skills --skill cross-wave-delta-analysis

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

84/100

Category

Security

Supported Platforms

Universal

Tags

Our assessment of cross-wave-delta-analysis

cross-wave-delta-analysis scores 84/100 on our quality scale, 684th of 971 Security skills we index.

Its SKILL.md is 5.0 KB long, well organised into 17 sections with 2 code examples: a solid amount of guidance for an agent.

With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
26/30
Structure
18/20
Description
12/15
Adoption
13/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 29 days ago, so cross-wave-delta-analysis is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

cross-wave-delta-analysis compared with similar skills

All 4 of these similar skills score higher than cross-wave-delta-analysis; compare them before choosing.

SkillScoreStarsUpdatedFormat
cross-wave-delta-analysis (this skill)by uphiago841.3k29d agoSKILL.md
algorithmic-artby anthropics100177.9k8d agoSKILL.md
pptxby anthropics100177.9k8d agoSKILL.md
designby nextlevelbuilder100130.2k9d agoSKILL.md
ui-ux-pro-maxby nextlevelbuilder100130.2k9d agoSKILL.md

Frequently asked questions

How do I install cross-wave-delta-analysis?
Run npx skills add uphiago/recon-skills --skill cross-wave-delta-analysis. The install tabs above show the steps for each supported agent.
Which AI agents does cross-wave-delta-analysis work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is cross-wave-delta-analysis safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is cross-wave-delta-analysis still maintained?
The repository was last updated 29 days ago, so cross-wave-delta-analysis is actively maintained.

name: cross-wave-delta-analysis description: Compare recon waves to find NEW, REGRESSED, PERSISTENT findings. version: 1.1.0 revision_date: 2026-07-25 license: MIT platforms: [linux] compatibility: N/A (analysis methodology) tags: [meta, wave, delta, comparison, analysis] category: meta related_skills:

  • recon-playbook
  • cross-attack-chains
  • cors-credential-wordpress
  • xmlrpc-exploitation
  • attack-patterns-reference

Cross-Wave Delta Analysis Skill

Methodology for comparing findings across multiple recon waves on the same target set. Detects NEW findings, REGRESSIONS (previously open now blocked), PERSISTENT vulnerabilities, and CHANGES over time. Distilled from 9 waves across 7 deep targets that revealed missed CORS findings, new port exposures, and infrastructure drift.

When to Use

  • Running repeated recon on the same target set (Wave N+1 after Wave N).
  • You want to know if a vulnerability was PATCHED since last wave.
  • You want to know if a NEW surface appeared (new ports, new subdomains, new endpoints).
  • After completing a deep recon wave — produce the delta report before next wave.
  • Before reporting — confirm findings are still valid (not regressed).

Prerequisites

  • Prior assessment output beneath ${OUTPUT_DIR:-./output}/baseline/.
  • Current assessment output beneath ${OUTPUT_DIR:-./output}/current/.
  • Structured findings per target (at minimum: ports, CORS status, WP users, XMLRPC status, sensitive paths).

How to Run

# Produce a delta report comparing WaveN to WaveN+1
# Read wave outputs, compare per-target, classify findings

Quick Reference

Delta Categories

| Category | Label | Meaning | Example | |----------|-------|---------|---------| | NEW | ++ | Finding that didn't exist in any prior wave | Port 3306 (MySQL) now OPEN | | REGRESSION | -- | Service that was accessible but is now blocked | XMLRPC 200 -> 405 (hardened) | | PERSISTENT | == | Vulnerability unchanged across all waves | CORS still reflecting since wave6 | | CHANGE | ~ | Configuration changed but not a regression | WP users: 10 in wave7, 9 in wave9 | | REVERSED | -> | A regression that was later undone (mitigation removed) | XMLRPC 405 (W9) -> 200 active (W10) |

REVERSED — Special Category

Reversed findings are regressions that later reverted to the original vulnerable state. This happens when:

  • A WAF rule was applied temporarily then removed (common on GoDaddy/Cloudflare shared hosting)
  • A plugin security update was rolled back
  • Infrastructure was redeployed without the hardening

Treat REVERSED as actionable: the security team either doesn't know or doesn't care. These targets are high-priority because their protection is unreliable.

Fields to Compare Per Target

| Field | How to Check | What Delta Means | |-------|-------------|------------------| | XMLRPC status | HTTP status of POST /xmlrpc.php | 200 -> 405 = REGRESSION (hardened) | | CORS headers | ACAO + ACAC on /wp/v2/users | Reflecting -> No headers = REGRESSION | | WP Users | Count from /wp/v2/users | Count change = CHANGE | | Open ports | nmap or naabu output | New port = NEW (surface expanded) | | Subdomains | subfinder output | New subs = NEW | | Sensitive paths | HTTP status for .env, info.php, etc | Previously 200 -> 403 = REGRESSION |

Procedure

Step 1 — Gather Both Waves' Data

WAVE_OLD="${OUTPUT_DIR:-./output}/baseline"
WAVE_NEW="${OUTPUT_DIR:-./output}/current"
echo "=== Comparing $WAVE_OLD vs $WAVE_NEW ==="

Step 2 — Produce Per-Target Delta Table

For each target present in both waves, compare XMLRPC status, CORS headers, open ports, WP users, and subdomains. Flag findings as NEW (not in prior wave), REGRESSION (previously working, now blocked), PERSISTENT (unchanged), or CHANGE (different but not blocked).

Step 3 — Classify & Flag Critical Deltas

Signal critical deltas: new port 3306 (MySQL), new CORS credential reflections, new WP install pages, new subdomains with admin/staging patterns.

Pitfalls

  • False REGRESSION. A 403 may be rate limiting, not patching. Retry 3x with different IPs/delays.
  • False PERSISTENT. A 200 endpoint may still be live but the underlying vulnerability (e.g., multicall) may be disabled.
  • Timing matters. Waves must use the same methodology or deltas are meaningless.
  • Don't confuse "not documented" with "not present." A finding may have existed but was simply missed.

Verification

  • Every delta must be reproducible with the exact same command on both waves' output.
  • NEW findings should be re-tested immediately — they may be transient.
  • PERSISTENT findings across 3+ waves are the most reliable (no security team, no patching cadence).

Related Skills

  • attack-patterns-reference — match findings to pattern IDs (P-01 to P-25)
  • recon-playbook — the 4-phase pipeline that produces wave data
  • cross-attack-chains — chain NEW findings into critical impact
  • cors-credential-wordpress — verify CORS findings classification
  • xmlrpc-exploitation — verify XMLRPC regression status

Related Skills

View on GitHub
GitHub Stars1.3k
CategorySecurity
Updated29d ago
Forks215

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions