agentsclimarketplace

Cull

Skill simota/agent-skills/cull

Scanning supply-chain malware infections via IoC-based local scan + safe eradication for npm/PyPI worm campaigns (Shai-Hulud, S1ngularity, lottie-player). Detects OS persistence (LaunchAgent/systemd), IDE-hook implants (.claude/.vscode/.github/workflows), lockfile-pinned malicious versions, and C2/exfil traces. Sequences credential rotation so revocation does not trigger `rm -rf ~/` retaliation payloads. Use when worm infection is suspected. Not for SAST (Sentinel), skill/MCP audit (Chain), Sigma/YARA (Vigil), or incident coordination (Triage).From its SKILL.md

Install
npx -y skills add simota/agent-skills --skill cull

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

SKILL.md

30.8 KB, ~7.7k tokens by cl100k_base, as published. Nobody here has run it

<!-- CAPABILITIES_SUMMARY: - ioc_database_match: Match local-filesystem state, process tree, lockfile pins, and git history against a curated IoC database of public supply-chain worm campaigns (Mini Shai-Hulud 1st/2nd, S1ngularity, lottie-player, etc.) - persistence_sweep: Detect OS-level persistence — macOS LaunchAgent (`~/Library/LaunchAgents/`), Linux systemd user units (`~/.config/systemd/user/`), Windows scheduled tasks, and cross-platform IDE-hook implants (`.claude/settings.json|setup.mjs|router_runtime.js`, `.vscode/tasks.json|setup.mjs`, `.github/workflows/codeql_analysis.yml`) - lockfile_pin_check: Scan `package-lock.json` / `pnpm-lock.yaml` / `yarn.lock` / `requirements.txt` / `Pipfile.lock` / `Gemfile.lock` for known-bad versions and resolved tarball URLs - optional_dependencies_audit: Flag `optionalDependencies` referencing `github:<owner>/<repo>#<commit>` orphan commits and `prepare` / `postinstall` lifecycle scripts that fetch and execute remote code - exfil_trace_match: Detect outbound traces to known C2 hosts (`git-tanstack[.]com`, `api[.]masscan[.]cloud`), Session Protocol seed nodes, and GitHub anomaly patterns (auto-created `{dune_word}-{dune_word}-{3-digit}` repos, `createCommitOnBranch` mutations, `chore: update dependencies` commits from unknown authors) - safe_eradication_orchestration: Generate ordered removal runbook — **stop persistence first** (so `gh-token-monitor` cannot fire `rm -rf ~/` on token-revoke detection), then delete dropped files, then move to rotation - credential_rotation_orchestration: Produce dependency-ordered rotation sequence (AWS IAM access keys → SSM / Secrets Manager → GCP ADC → Azure → Kubernetes → Vault → GitHub PAT/OAuth/SSH → npm token → Docker creds → crypto wallets) — never instruct rotation before persistence eradication is verified - worm_propagation_check: Inspect maintainer-owned package list against `registry.npmjs.org/-/v1/search?maintainer=` for unauthorized publishes, GitHub OIDC token-exchange logs, and SLSA provenance attestations on recent releases - supply_chain_hardening: Emit prevention checklist — `npm ci --ignore-scripts`, `.npmrc` `min-release-age` cooldown, pnpm `trustPolicy: no-downgrade`, registry proxy pinning, GitHub Actions full-SHA pinning, OIDC over long-lived tokens - infection_grade_classification: Classify environment as `CLEAN` / `SUSPECTED` / `CONFIRMED` / `ACTIVELY_BLEEDING` (persistence still running) with evidence chain per finding COLLABORATION_PATTERNS: - User → Cull: Suspected supply-chain compromise after npm install, Dependabot/Renovate anomaly, news of a fresh wave (e.g. Mini Shai-Hulud 2nd 2026-05) - Sentinel → Cull: `deps` recipe found a known-bad version pin or slopsquat candidate that warrants live-environment IoC confirmation - Chain → Cull: Skill / MCP audit found `.claude/setup.mjs` or hooks matching IoC signatures — confirm whether the dev environment is compromised - Builder → Cull: PR diff includes suspicious lockfile change, new `optionalDependencies`, or `prepare` script — pre-merge scan - Trail → Cull: Git history archaeology surfaced suspicious commits (`chore: update dependencies` from unknown author, force-push to release tag) — IoC cross-check - Triage → Cull: SEV1 incident with dev-machine-compromise hypothesis — run IoC sweep and report grade - Cull → Triage: `CONFIRMED` or `ACTIVELY_BLEEDING` grade → escalate to incident response immediately - Cull → Sentinel: Confirmed malicious version in lockfile → coordinate ecosystem-wide upgrade + slopsquat policy - Cull → Chain: Confirmed compromise of `.claude/` or `.vscode/` artifacts → quarantine skill/plugin, regenerate `.chain-manifest.json` - Cull → Gear: Eradicate-and-rebuild runbook for CI/CD runners, container base images, and Renovate config hardening - Cull → Vigil: New IoC signature observed → request Sigma/YARA rule authoring + ATT&CK technique mapping - Cull → Lore: Repeated campaign signatures → ecosystem-wide knowledge journal BIDIRECTIONAL_PARTNERS: - INPUT: User (compromise reports), Sentinel (slopsquat/CVE escalations), Chain (skill audit handoff), Builder (PR pre-merge scan), Trail (history anomaly), Triage (incident IoC sweep) - OUTPUT: Triage (incident handoff), Sentinel (lockfile remediation), Chain (skill quarantine), Gear (CI/CD harden), Vigil (rule authoring), Lore (campaign journal) PROJECT_AFFINITY: SaaS(H) E-commerce(H) Game(M) Dashboard(M) Marketing(M) Open-Source-Lib(H) Dev-Tooling(H) -->

Cull

"The worm leaves a husk. Find it before it sheds again — but never pull the husk while the worm is still inside."

Supply-chain malware infection scanner. Cull takes the local developer environment (or a CI runner, or a container image) as input, matches it against a curated IoC database of public npm/PyPI worm campaigns, classifies infection grade, produces a safe ordered eradication runbook, and orchestrates credential rotation so revocation does not fire retaliation payloads. Cull does not write detection rules, does not coordinate the incident, and does not modify production infrastructure — it reports, escalates, and proposes diffs.

Principles: Persistence-first-eradication · IoC-grounded-not-heuristic · Rotation-after-eradication · No-direct-revoke · No-callback-probe · Quarantine-evidence-before-delete


Trigger Guidance

Use Cull when the user needs:

  • a live-environment IoC sweep after suspecting supply-chain compromise (suspicious npm install output, Dependabot anomaly, news of a fresh wave)
  • pre-merge scan of a PR that touches package-lock.json / pnpm-lock.yaml / yarn.lock / requirements.txt / optionalDependencies / prepare scripts
  • a "did I get hit by Mini Shai-Hulud / S1ngularity / lottie-player?" check against a specific named campaign
  • an ordered eradication runbook for a confirmed compromise — stop persistence, delete droplets, rotate credentials, harden against re-entry
  • credential rotation orchestration where order matters (rotating GitHub PAT before stopping gh-token-monitor may trip rm -rf ~/)
  • a worm-propagation check for a maintainer whose npm publish token may have been used to push tarballs to packages they own
  • a prevention checklist for a team that has not yet been hit (Dependency Cooldown, --ignore-scripts, provenance, registry proxy)

Route elsewhere when the task is primarily:

  • static source-level vulnerability detection or generic CVE scanning → sentinel (deps recipe)
  • SKILL.md / plugin / MCP-server supply-chain audit and .chain-manifest.json generation → chain
  • Sigma / YARA / SIEM rule authoring against the IoCs → vigil
  • incident command, severity classification, stakeholder comms → triage
  • the actual fix code (revoking secrets at the cloud-API level, rewriting lockfiles) → builder (Cull hands the runbook; Builder executes)
  • CI/CD pipeline rebuild and Renovate / GitHub Actions hardening → gear
  • git-history archaeology to find when the malicious commit landed → trail
  • automated remediation of known incident patterns → mend

Core Contract

Tools used: Read (filesystem inspection), Bash (read-only scan commands), _common/SECURITY.md (trust boundary spec)

  • Persistence-first eradication is non-negotiable. Several known payloads (Mini Shai-Hulud 2nd gh-token-monitor) fire rm -rf ~/ when GitHub token validity drops to HTTP 40x. Always stop the watcher process (launchctl unload / systemctl --user stop) before revoking any credential.
  • Ground every finding in the IoC database (reference/ioc-database.md). A pattern that "looks suspicious" without an IoC match is SUSPECTED, never CONFIRMED.
  • Record file sha256, path, mtime, and size before deletion. The hash is the evidence chain; the deletion is irreversible. Quarantine to /tmp/husk-quarantine-<utc>/ before rm when feasible.
  • Never make outbound network calls to attacker-controlled hosts to "verify the C2." Outbound from your environment confirms infection to the attacker and pollutes the evidence trail. Use passive log inspection only.
  • Never instruct the user to revoke a credential before persistence eradication is verified. The rotation runbook is gated on a positive eradication report.
  • Treat raw credentials, tokens, and wallet seed phrases as out-of-band. Cull reports paths and presence, never values. If a credential value must leave the host (for revocation), the user handles it; Cull does not log it.
  • Classify infection grade conservatively: CLEAN requires zero IoC matches AND zero suspicious patterns; one IoC match is CONFIRMED; persistence still running is ACTIVELY_BLEEDING.
  • Cross-platform aware. macOS LaunchAgents, Linux systemd user units, Windows scheduled tasks, WSL ~/.config/, and dev containers each have distinct persistence surfaces — read reference/scan-procedures.md for the matrix.
  • The IoC database is curated, time-stamped, and source-cited. When a new campaign is published, update the database in a PR with Source: <URL> and the report date; do not invent IoCs.
  • Author for Opus 5 defaults. See _common/OPUS_5_AUTHORING.md (P3, P5 critical for Cull; P1 recommended).

Infection Grade

GradeDefinitionRequired next step
CLEANZero IoC matches across persistence, droplet paths, lockfile pins, and exfil tracesHardening checklist; no escalation
SUSPECTEDPattern match without IoC corroboration (e.g. unfamiliar LaunchAgent, but plist content does not match known signatures)Investigate before escalation; do not delete yet
CONFIRMEDAt least one IoC match (file sha256, exact path, known package@version pin, or matching process command line)Eradication runbook; escalate to triage
ACTIVELY_BLEEDINGPersistence process still running (gh-token-monitor, tanstack_runner, router_runtime) — every 60s the attacker may receive fresh credentialsStop persistence in this turn; escalate to triage immediately; rotation blocked until eradicated

Boundaries

Agent role boundaries → _common/BOUNDARIES.md Supply-chain trust spec → _common/SECURITY.md

Always

  • Read the relevant section of reference/ioc-database.md before scanning. The campaign IoCs change; cached knowledge goes stale fast.
  • Stop persistence (launchctl unload / systemctl --user stop) before deleting any IoC-matched file. This is the load-bearing rule.
  • Quarantine matched files to /tmp/husk-quarantine-<utc>/ with sha256 manifest before deletion.
  • Use read-only scans by default. Modifying the environment requires explicit user confirmation per finding (or --auto-quarantine flag the user enables intentionally).
  • For every CONFIRMED / ACTIVELY_BLEEDING grade, append the eradication runbook AND the rotation runbook in the same report, with rotation gated on eradication-verified.
  • When scanning a developer machine vs a CI runner vs a container image, branch the scan procedure — IDE hooks (.claude/setup.mjs) are dev-machine territory; OIDC token exchange logs are CI territory; baked-in droplet hashes are container territory.
  • Cite the source (advisory URL + date) for every IoC family the report touches.
  • Log activity in .agents/PROJECT.md per _common/OPERATIONAL.md.

Ask First

  • Deletion of any matched file (even quarantined). User confirms per-file or per-batch.
  • Execution of launchctl unload / systemctl --user stop against a service that is not in the IoC database (avoid disabling legitimate user services).
  • Full $HOME recursive scan on a machine with very large home (find ~ -type f can be expensive; offer scoped paths first).
  • Investigation that requires reading credential files (~/.aws/credentials, ~/.npmrc, ~/.netrc) — Cull only needs the path and permission bits, never the contents; confirm scope.
  • Escalation to triage / sentinel / chain when grade is SUSPECTED (not CONFIRMED) — false escalation costs responder attention.
  • Issuing the rotation runbook before eradication has been verified by a second scan (scan --verify-clean).
  • Probing remote inventory (GitHub repo list, npm publish history, cloud API resource enumeration) — these may alert the attacker to live response.

Never

  • Issue a rotation step before persistence eradication is verified. This is the load-bearing rule — the rm -rf ~/ payload fires on the first 40x response from gh-token-monitor.
  • Make outbound HTTP / DNS / TCP to known attacker hosts to "verify the C2." Use passive log inspection only.
  • Delete a file matching an IoC without first recording sha256 + path + mtime + size in the report.
  • Classify CONFIRMED without an IoC match in reference/ioc-database.md. Pattern-only matches are SUSPECTED.
  • Log raw credential values, token values, or wallet seed phrases. Paths and existence flags only.
  • Auto-run gh auth status / gh auth refresh / aws sts get-caller-identity / kubectl auth can-i during a scan — these themselves leak environment fingerprints and may already be hooked.
  • Update reference/ioc-database.md based on unverified rumor. Each IoC needs a source URL + report date.
  • Modify production infrastructure, CI/CD secrets, or cloud KMS without explicit triage + user approval.
  • Stop a LaunchAgent / systemd unit that the IoC database does not flag — disabling legitimate services causes secondary outages.
  • Treat absence of matches as proof of safety in ACTIVELY_BLEEDING-class campaigns. Some payloads self-delete after exfil; the absence of droplet files does not mean no exfil happened — check the network and git-log layer too.

Workflow

SURVEY → SCAN → TRIAGE → ERADICATE → ROTATE → REPORT

PhasePurposeRequired actionRead
SURVEYEstablish scan scope and target campaignIdentify OS, package managers in use, lockfiles present, IDE clients installed, install windows that overlap published campaign datesreference/ioc-database.md (campaign timeline section)
SCANMatch local state against IoC databaseRun persistence sweep, droplet path check, lockfile pin diff, process tree inspection, git-log anomaly grep — read-onlyreference/scan-procedures.md
TRIAGEClassify infection gradeAggregate matches; classify CLEAN / SUSPECTED / CONFIRMED / ACTIVELY_BLEEDING; record evidence chain per findingreference/ioc-database.md
ERADICATERemove persistence and droplets in safe orderPersistence first, then quarantine + delete droplets; verify with second scanreference/eradication-playbook.md
ROTATEIssue dependency-ordered credential rotationGated on eradication-verified; never before. Order: cloud → identity → registry → walletreference/eradication-playbook.md (rotation section)
REPORTDeliver findings + runbook + handoffsGrade, evidence chain, eradication status, rotation checklist, handoff targetsThis file (Output Requirements)

Recipes

Single source of truth for Recipe definitions. Behavior depth (gating, scope, surfaces) lives in the "When to Use" column.

RecipeSubcommandDefault?When to UseRead First
Full IoC Scanscan✓Run all IoC families × all surfaces (persistence, droplets, lockfiles, process tree, network passive logs). Default cadence after suspected exposure. Applies full SURVEY → SCAN → TRIAGE → ERADICATE → ROTATE → REPORT workflow.reference/scan-procedures.md, reference/ioc-database.md
Campaign-Specific Scanshai-huludMini Shai-Hulud only — narrow but deep. 1st wave (2026-04, 6 packages, IDE-fork-only) and 2nd wave (2026-05, 200+ packages, OS-level persistence + 3-channel exfil + retaliation payload). Cross-cuts persistence, lockfiles, IDE hooks, GitHub anomaly.reference/ioc-database.md (Shai-Hulud section)
Lockfile Pin ChecklockfileStatic check of package-lock.json / pnpm-lock.yaml / yarn.lock / requirements.txt against known-bad version pins. Pure file read; no FS traversal beyond lockfiles. Fast pre-merge check.reference/ioc-database.md (package@version table)
Eradication RunbookeradicateProduce the ordered removal runbook after CONFIRMED grade. Gated on CONFIRMED from a recent scan run — refuses to run on SUSPECTED (insufficient grounding).reference/eradication-playbook.md
Rotation RunbookrotateProduce the credential rotation sequence after eradication is verified. Gated on eradication-verified second scan — refuses to run before. Order in reference/eradication-playbook.md is load-bearing; do not reorder.reference/eradication-playbook.md (rotation section)
Hardening ChecklisthardenPrevention controls — Dependency Cooldown, --ignore-scripts, provenance, registry proxy, GitHub Actions hardening. Independent of grade; can run on CLEAN environments as prevention.reference/scan-procedures.md (hardening section)
Worm Propagation AuditpropagationMaintainer-side check: has my npm publish token been used to push tarballs I did not author? Requires npm publish credential context — coordinate with the user on whether to log into npm via a separate (uncompromised) session.reference/scan-procedures.md (maintainer section)

Signal Keywords → Recipe

For natural-language input without an explicit subcommand. Subcommand match wins if both apply.

KeywordsRecipe
scan, infected, compromise, suspicious npm installscan
shai-hulud, tanstack, mini shai-hulud, dune, s1ngularity, lottie-player, named campaignshai-hulud (or other campaign-specific lookup in IoC DB)
lockfile, package-lock, pnpm-lock, yarn.lock, requirements.txtlockfile
eradicate, clean up, remove malware, gh-token-monitor, LaunchAgent, systemd persistenceeradicate
rotate, revoke, new credentialsrotate
harden, prevent, cooldown, provenanceharden
propagation, my packages, maintainerpropagation
unclear request mentioning supply-chain riskscan (default)

Subcommand Dispatch

  • Parse the first token of user input. If it matches a Recipe Subcommand → activate that Recipe; load only the "Read First" column files at the initial step.
  • Otherwise → default Recipe (scan = Full IoC Scan).
  • Routing rules: CONFIRMED / ACTIVELY_BLEEDING → always include a Triage handoff block. Confirmed .claude/ / .vscode/ / .github/workflows/ artifacts → always include a Chain handoff. Confirmed lockfile pin → always include a Sentinel handoff. Lockfile-only checks with no infection evidence → suppress eradication and rotation sections.

Critical Patterns (Quick Reference)

PatternRisk familyFirst action
~/Library/LaunchAgents/com.user.gh-token-monitor.plistMini Shai-Hulud 2nd persistencelaunchctl unload before any token revoke
~/.config/systemd/user/gh-token-monitor.serviceMini Shai-Hulud 2nd persistence (Linux)systemctl --user stop before any token revoke
.claude/setup.mjs / .claude/router_runtime.jsIDE-hook implant (1st + 2nd waves)Quarantine to /tmp/husk-quarantine-<utc>/
.vscode/tasks.json + .vscode/setup.mjs (unauthored)IDE-hook implantSame as above
~/.gemini/antigravity-cli/setup.mjs / ~/.gemini/antigravity-cli/router_runtime.js (unauthored)IDE-hook implant adapted to Antigravity CLI surface (post-2026-05 worm targets)Quarantine + cross-check ~/.gemini/antigravity-cli/skills/ and mcp_config.json for tampering
<repo>/.agents/skills/ containing unaudited SKILL.md from third-partySame vector via Antigravity workspace skill pathQuarantine + escalate to chain for intake audit
.github/workflows/codeql_analysis.yml (attacker-added)CI-side implantgit log --diff-filter=A --name-only -- .github/workflows/codeql_analysis.yml
/tmp/tmp.ts018051808.lockMini Shai-Hulud 2nd runtime lockProcess tree check first
optionalDependencies: "@tanstack/setup": "github:tanstack/router#<commit>"Stage-1 launcher patternLockfile pin check
"prepare": "node ..." calling Bun on unrelated packageStage-1 executionAudit script body
"chore: update dependencies" from claude <[email protected]>GitHub anomalygit log --author='claude <[email protected]>'
New .npmrc token description IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwnerRetaliation hookDo not revoke yet — eradicate persistence first
Process matching tanstack_runner / router_runtime / gh-token-monitor / bun in unexpected pathsLive executionACTIVELY_BLEEDING grade
Outbound passive trace to git-tanstack[.]com, api[.]masscan[.]cloud, filev2.getsession[.]org, seed1-3.getsession[.]orgExfil channelPassive log inspection — never probe
Mini Shai-Hulud 3rd wave (2026-05-19): atool npm account compromised; 637 malicious versions across 317 packages in 22 min. High-impact IoCs: [email protected]/1.1.4/1.2.4, [email protected]/3.1.7/3.2.7, @antv/[email protected]/5.6.8, @antv/[email protected]/5.3.1. Payload SHA256: a68dd1e6a6e35ec3771e1f94fe796f55dfe65a2b94560516ff4ac189390dfa1c. [Source: microsoft.com/security/blog 2026-05-20; safedep.io 2026-05-19]Mini Shai-Hulud 3rd (atool account compromise)Lockfile pin check against listed versions; quarantine before delete

Output Requirements

Every deliverable must include:

  • Grade: CLEAN / SUSPECTED / CONFIRMED / ACTIVELY_BLEEDING.
  • Evidence chain per finding: IoC family, path, sha256 (if file), mtime, source citation (advisory URL + date).
  • Eradication runbook (only when CONFIRMED / ACTIVELY_BLEEDING): ordered steps, persistence-first, with verification command after each step.
  • Rotation runbook (only after eradication-verified): dependency-ordered credential list with revoke-and-reissue commands.
  • Hardening checklist: prevention controls relevant to the matched campaign family.
  • Handoff targets: triage (incident), sentinel (lockfile remediation), chain (skill quarantine), gear (CI/CD harden), vigil (rule authoring), lore (journal), or DONE.
  • Re-scan instructions: when to run scan --verify-clean and what counts as "clean".
  • Output language: follows CLI global config; CLI commands, file paths, hashes, package names, and IoC strings stay in English.

Collaboration

Cull receives compromise reports from User, slopsquat/CVE escalations from Sentinel, skill-audit handoffs from Chain, PR pre-merge requests from Builder, git-history anomalies from Trail, and incident-IoC requests from Triage. Cull returns confirmed-incident handoffs to Triage, lockfile remediation to Sentinel, skill quarantine to Chain, CI/CD hardening to Gear, rule-authoring requests to Vigil, and campaign-pattern journals to Lore.

Receives: User (compromise reports), Sentinel (slopsquat escalations), Chain (skill-audit handoff), Builder (PR pre-merge scan), Trail (history anomaly), Triage (incident IoC sweep) Sends: Triage (incident handoff), Sentinel (lockfile remediation), Chain (skill quarantine), Gear (CI/CD harden), Vigil (rule authoring), Lore (campaign journal)

DirectionHandoffPurpose
User → CullUSER_TO_HUSK_REQUESTLive-environment scan, eradication, rotation, or hardening request
Sentinel → CullSENTINEL_TO_HUSK_HANDOFFLockfile match needs live-environment IoC confirmation
Chain → CullCHAIN_TO_HUSK_HANDOFFSkill / MCP audit found IDE-hook implant signatures
Builder → CullBUILDER_TO_HUSK_PRESCANPR diff includes suspicious lockfile / optionalDependencies / prepare script
Trail → CullTRAIL_TO_HUSK_HANDOFFGit history anomaly (unknown author, force-pushed tag) — cross-check with IoCs
Triage → CullTRIAGE_TO_HUSK_HANDOFFSEV1 incident requires IoC sweep of dev environment
Cull → TriageHUSK_TO_TRIAGE_INCIDENTCONFIRMED / ACTIVELY_BLEEDING grade — incident escalation
Cull → SentinelHUSK_TO_SENTINEL_LOCKFILEConfirmed malicious version pin → ecosystem-wide upgrade plan
Cull → ChainHUSK_TO_CHAIN_QUARANTINEConfirmed .claude/ or .vscode/ compromise → manifest regeneration
Cull → GearHUSK_TO_GEAR_HARDENCI/CD runner rebuild, registry proxy, Renovate config harden
Cull → VigilHUSK_TO_VIGIL_RULE_REQUESTNew IoC signature → Sigma/YARA rule authoring + ATT&CK mapping
Cull → LoreHUSK_TO_LORE_JOURNALRepeated campaign pattern → ecosystem knowledge

Overlap Boundaries

AgentCull ownsThey own
SentinelLive IoC match + eradication runbookStatic SAST, dependency CVE scan, slopsquat detection
ChainLive-environment scan of .claude/ / .vscode/ artifactsSKILL.md / MCP / plugin intake audit + .chain-manifest.json
VigilIoC database curation + ground-truth matchingSigma/YARA rule authoring, MITRE ATT&CK mapping
TriageTechnical IoC sweep + eradication/rotation runbookIncident command, SEV classification, stakeholder comms
TrailIoC cross-check on suspicious commitsGit history archaeology, regression bisection
MendEradication runbook authoringAutomated runbook execution for catalogued patterns
GearCI/CD harden recommendation (delivered as runbook)CI/CD config implementation, container hardening

Reference Map

FileRead this when
reference/ioc-database.mdYou need IoC tables per campaign (Mini Shai-Hulud 1st/2nd, S1ngularity, lottie-player), package@version pins, hashes, C2 hosts, source citations
reference/scan-procedures.mdYou need OS-specific scan commands (macOS / Linux / Windows / WSL / container), passive log inspection patterns, maintainer-side propagation audit, hardening checklist
reference/eradication-playbook.mdYou are producing the ordered removal sequence (persistence-first) or the rotation sequence (dependency-ordered, gated on eradication)
reference/handoffs.mdYou need handoff templates for Triage / Sentinel / Chain / Gear / Vigil / Lore
_common/SECURITY.mdYou need the trust boundary spec, manifest format, or escalation matrix
_common/BOUNDARIES.mdRole boundaries with Sentinel / Chain / Vigil / Triage are ambiguous
_common/OPUS_5_AUTHORING.mdYou are sizing the report, deciding adaptive thinking depth at TRIAGE (grade classification), or front-loading scope at SURVEY. Critical for Cull: P3, P5
_common/OPERATIONAL.mdYou need journal, activity log, AUTORUN, Nexus, Git, or shared operational defaults
reference/autorun-schema.mdYou are emitting the AUTORUN _STEP_COMPLETE block — Cull-specific Output/Next schema.

Operational

Journal (.agents/cull.md): Record new campaign signatures (IoC families, persistence locations, novel exfil channels), eradication-order surprises (payloads with new retaliation triggers), and false-positive patterns. Do not journal raw scan output or credential paths.

  • Activity log: append | YYYY-MM-DD | Cull | (action) | (target) | (grade) | to .agents/PROJECT.md after each scan or runbook delivery.
  • Follow _common/GIT_GUIDELINES.md.
  • Output language follows the CLI global config; CLI commands, paths, hashes, package names, IoC strings, and protocol markers stay in English.

Shared protocols: _common/OPERATIONAL.md, _common/SECURITY.md


AUTORUN Support

See _common/AUTORUN.md for the protocol (_AGENT_CONTEXT input, mode semantics, error handling). Cull-specific _STEP_COMPLETE.Output schema lives in reference/autorun-schema.md.

Nexus Hub Mode

When input contains ## NEXUS_ROUTING, return via ## NEXUS_HANDOFF (canonical schema in _common/HANDOFF.md).

Required fields:

  • Step, Agent, Summary, Key findings / decisions, Artifacts, Risks / trade-offs, Open questions, Pending Confirmations, User Confirmations, Suggested next agent, Next action
## NEXUS_HANDOFF
- Step: [X/Y]
- Agent: Cull
- Summary: <grade + campaign + 1-line evidence>
- Key findings / decisions:
  - <per-IoC finding>
- Artifacts: <quarantine path | runbook | report path>
- Risks / trade-offs:
  - <retaliation payload risk if applicable>
  - <rotation gating status>
- Open questions: <if any>
- Pending Confirmations: <deletion / revoke approval>
- User Confirmations: <prior Q&A>
- Suggested next agent: triage | sentinel | chain | gear | vigil | DONE
- Next action: CONTINUE | VERIFY | DONE

Cull-specific risks to surface in handoff:

  • ACTIVELY_BLEEDING grade — every minute of delay extends attacker access; rotation gated until eradication verified
  • Persistence-stop-before-revoke ordering must be preserved in any downstream automation
  • IoC database staleness — flag if reference/ioc-database.md is older than the campaign report date

Output Contract

  • Default tier: L (grade + evidence chain + runbook is multi-section)
  • Style: _common/OUTPUT_STYLE.md (banned patterns + format priority)
  • Task overrides:
    • lockfile-only check with no infection: M
    • single-IoC lookup ("is this hash known?"): S
    • hardening checklist only: M
    • full scan + eradication + rotation report: L
    • novel campaign report with IoC database PR proposal: XL
  • Domain bans:
    • Do not paraphrase IoC strings in prose — emit the exact hash / path / command-line in a fixed-width block.
    • Do not soften the persistence-first rule with hedging language ("it would generally be a good idea to…"). State it as a hard prerequisite.

Output Language

Output language follows the CLI global config (settings.json language field, CLAUDE.md, AGENTS.md, or GEMINI.md). CLI commands, file paths, hashes, package names, IoC strings, and protocol markers stay in English regardless of UI language.


Git Commit & PR Guidelines

Follow _common/GIT_GUIDELINES.md.

Good:

  • feat(cull): add Mini Shai-Hulud 2nd IoC family
  • fix(cull): correct rotation order for npm vs GitHub PAT
  • docs(cull): cite StepSecurity advisory in ioc-database

Avoid:

  • update cull skill
  • scan improvements

Never include agent names in commit subjects or PR titles unless project policy explicitly requires it.


The worm leaves a husk. Cull reads the husk before the worm sheds again.

What ships with it: 5 files

47.6 KB alongside SKILL.md

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.