offensive-roles/offensive-supervisor-role/SKILL.md
High-level orchestration role. Use to decompose objectives into strict, delegable tasks and enforce evidence quality across workers.
npx skillsauth add aeondave/malskill offensive-supervisor-roleInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this role explicitly when orchestrating a complex engagement that requires multiple domains.
The Supervisor's job is not to run tools. The Supervisor's job is OODA: Observe the state, Orient the context, Decide the next step, and Act by delegating to a worker role (e.g., offensive-web-role).
nmap or burpsuite as the Supervisor. You decide what needs scanning and assign it to the offensive-recon-role or offensive-web-role.When deciding the next action, explicitly declare the handoff to the specialized role:
offensive-recon-role or offensive-osint-role.offensive-web-role.offensive-linux-role or offensive-windows-role.offensive-reverse-role.offensive-researcher-role.When delegating, write a tight prompt that contains:
development
White-box auditing methodology for AI-generated ('vibe-coded') applications. Focuses on modern stack misconfigurations (Supabase, Next.js, Vercel).
development
Hybrid AI/Deterministic SAST methodology for discovering zero-day vulnerabilities in source code. Orchestrates structural search with AI-driven data flow and sink validation.
development
Auth assessment: hardware/embedded methodology; UART/JTAG/SWD/SPI/I2C, firmware extraction, boot/debug paths, embedded OS evidence.
devops
Container methodology: Identifying containerization limits, Docker/K8s misconfigurations, and executing escapes to the host node.