agentsclimarketplace

Engagement flow

Skill hypnguyen1209/offensive-claude/skills/engagement-flow

Use when starting, planning, or running a multi-phase pentest or red-team engagement — to sequence the Cyber Kill Chain phases with quality gates instead of jumping straight to exploitationFrom its SKILL.md

Install
npx -y skills add hypnguyen1209/offensive-claude --skill engagement-flow

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • runs commandsInstructs the agent to run 8 commands, including `/engage.scope` and 7 more.

SKILL.md

3.1 KB, 728 tokens by cl100k_base, as published. Nobody here has run it

Engagement Flow

Overview

A pentest/red-team engagement is a phased pipeline with gates, not a pile of techniques run ad hoc. This skill sequences the 9-phase Lockheed Martin Cyber Kill Chain and routes each phase to its commands, domain skills, and discipline checks. It is the offensive analog of brainstorming → writing-plans → executing-plans: scope the work, plan it, then execute phase by phase.

Don't jump to exploitation. Earlier phases earn the access that later phases need, and each gate keeps quality high before you advance.

The pipeline

digraph killchain {
    rankdir=LR;
    scope -> recon -> weaponize -> deliver -> exploit -> install -> c2 -> actions -> report;
    scope [label="0 SCOPE"]; recon [label="1 RECON"]; weaponize [label="2 WEAPONIZE"];
    deliver [label="3 DELIVER"]; exploit [label="4 EXPLOIT"]; install [label="5 INSTALL"];
    c2 [label="6 C2"]; actions [label="7 ACTIONS"]; report [label="8 REPORT"];
}

Each transition requires a gate (/engage.gate): required artifacts present, findings carry CWE+CVSS+ATT&CK+evidence, and the automated checks pass. Gate FAIL → fix the gap before advancing.

How to run it

  1. Pick the workflow preset for the engagement type (web-app, network, red-team, cloud, mobile, ad-domain, bug-bounty) and drive phases with the /engage.* commands.
  2. Phase 0 (scope): emit .engage/scope/scope.json. REQUIRED: scope-discipline.
  3. Phases 1-7: before any target interaction → scope-discipline; before any outward action → opsec-discipline; invoke the matching domain skill for the technique.
  4. Recall prior intel: at recon/weaponize, /engage.memory recall to start from what worked.
  5. Findings: REQUIRED: finding-discipline — nothing is [CONFIRMED] without proof.
  6. Phase 8 (report): record confirmed findings to engagement-memory; generate the report.
  7. Optional autopilot: engine/engine.py runs the phases under a budget/loop/trace with --resume (/engage.pickup); offensive actions stay operator-gated.

Red Flags — STOP, back up a phase

  • "Let me just start exploiting" (no scope.json / no recon → back to phase 0/1)
  • "Skip the gate, I'll document later" (gates exist so the report is complete and findings are real)
  • "Recon is done, I didn't check prior intel" (run /engage.memory recall)

Quick reference

PhaseCommandDiscipline / tooling
Scope/engage.scopescope-discipline → scope.json
Recon/engage.reconscope-discipline; /engage.memory recall
Exploit/engage.exploitopsec-discipline; finding-discipline
Actions/engage.actionsaction_guard gate; opsec-discipline
Report/engage.reportfinding-discipline; record to memory
Gate / resume/engage.gate, /engage.pickupautomated checks; engine trace

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Gives 0 of the 12 instructions most social media skills give in 728 tokens

Counted across 400 of the 422 authors here whose files we hold, read 2026-09-06

  • Build content around three to five pillarsin 40 of 400, across 16 files
  • Read product marketing context before asking questionsin 37 of 400, across 15 files
  • Gather goals, audience, brand voice, and resourcesin 35 of 400, across 13 files
  • Maintain one to two weeks of scheduled contentin 27 of 400, across 8 files
  • Batch content creation in weekly sessionsin 23 of 400, across 7 files
  • Review top and bottom posts weeklyin 22 of 400, across 7 files
  • Run the quality gate before deliveringin 20 of 400, across 11 files
  • Add subtitles to all social videoin 20 of 400, across 7 files
  • Write standalone captions that work without contextin 20 of 400, across 7 files
  • Prefer specificity over adjectivesin 19 of 400, across 10 files
  • Respond to all comments on your postsin 18 of 400, across 6 files
  • Carry one actual claim per postin 18 of 400, across 9 files

Said here and by no other author read

  • Pick a workflow preset for the engagement type
  • Run phases in kill chain order
  • Pass each gate before advancing
  • Emit scope.json during the scope phase
  • Apply scope-discipline before any target interaction
  • Apply opsec-discipline before any outward action

Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.