Attack Flow
Generates SITF-compliant attack flow JSON from supply chain or breach reports.
In test queue
Test report
- Verdict
- In test queue
- Tested
- —
- Environment
- Pending
In the test queue — machine-screened (validator 85/100, 171★ repo), full install/trigger/output test scheduled.
What Attack Flow does
Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports. Use when analyzing supply chain attacks, breaches, or security incidents.
How to install Attack Flow
git clone https://github.com/wiz-sec-public/SITF
cp -r SITF/.claude/skills/attack-flow ~/.claude/skills/attack-flow
Skills live in ~/.claude/skills/ (global) or .claude/skills/
(per-project). Restart Claude Code after installing.
Commands — how to trigger Attack Flow
-
/attack-flowGenerates SITF-compliant attack flow JSON from supply chain or breach reports.
It also activates on plain-language prompts like these:
-
Generate an attack flow JSON from this breach report -
Model this supply chain attack as a SITF flow -
Convert this incident writeup into an attack flow diagram
Frequently asked questions
- Is the Attack Flow skill free?
- Yes. The skill itself is free from wiz-sec-public/SITF. SkillProof publishes the install command and an independent test verdict at no cost.
- Does Attack Flow work with Claude Code?
- It is in our test queue — we run every skill on real work before issuing a verdict, and this one is scheduled.
- How do I install Attack Flow?
- Copy the install command from this page, run it in your terminal, and restart Claude Code. Skills live in ~/.claude/skills/ (global) or .claude/skills/ inside a project.
- Can I use Attack Flow with Cursor, Copilot, Gemini CLI, Codex or other AI tools?
- The SKILL.md format is native to Claude (Claude Code, Desktop, claude.ai). The instructions inside adapt to other assistants: Cursor rules, GitHub Copilot instructions, Windsurf rules, Custom GPTs, AGENTS.md for OpenAI Codex, and GEMINI.md for Google Gemini CLI — our conversion guides cover each, and the free converter on the tools page does the wrapping for you.