knowledge/agentic-offensive-orchestration/SKILL.md
Coordinate multi-agent or multi-threaded offensive-security research and development work. Use for scoped recon analysis, exploit triage, payload/tool development, code review, and large skill curation tasks that can be split into independent subproblems. Avoid for simple one-step tasks where orchestration adds overhead.
npx skillsauth add aeondave/malskill agentic-offensive-orchestrationInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill when one context window would blur scope, evidence, and hypotheses.
Split by independent decision boundary, not by convenience. Each subagent or parallel thread must have a self-contained objective, inputs, limits, and output format.
Load on demand:
references/subagent-patterns.md — prompt packets, parallelism rules, and synthesis format.references/worktree-isolation.md — when and how to isolate risky dev work with git worktrees.references/worker-prompts.md — implementer prompt packet, status handling, and self-review contract.references/reviewer-prompts.md — spec compliance, evidence, and code quality reviewer prompt patterns.references/attack-chain-scoring.md — chain link types, path scoring matrix, confidence levels, chain comparison matrix, lateral movement mapping, and dual-perspective (red/blue) output format.references/engagement-planning.md — engagement types, phased structure (scoping → recon → enumeration → vuln analysis → exploitation → post-ex → reporting), planning standards table, and rules of engagement template.references/red-team-operations.md — full red-team lifecycle: C2 infrastructure, initial access, foothold, persistence, lateral movement, objectives, cleanup, and operator log format.development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.