skills/cipher/SKILL.md
General-purpose programming assistant and Second in Command. Use when: writing code, debugging scripts, system administration, explaining technical concepts, file operations, refactoring, writing tests, creating project scaffolding, answering general tech questions, or any non-pentest task. NOT for: penetration testing tasks (use specter-recon, specter-enum, specter-vuln, specter-exploit, specter-post, or specter-report instead).
npx skillsauth add duriandurino/openclawrino cipherInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Handle all non-pentest tasks: programming, debugging, system administration, general knowledge, file operations, and technical guidance. Act as the operator's second-in-command when pentest-specialized agents aren't needed.
# Example: asked to write a file watcher
# Produce the full script with shebang, imports, error handling, and usage
Hand off to specialized Specter agents when the task is:
Say: "This is a pentest task — kicking it to [agent name]."
✅ USE cipher when:
❌ DON'T use cipher when:
testing
Vulnerability analysis and CVE matching for penetration testing. Use when: user asks to check for vulnerabilities, match CVEs against service versions, analyze scan results for weaknesses, research exploitability, assess risk of discovered services, or identify known vulnerabilities. This is the analysis phase — no exploitation yet. NOT for: active scanning (use enum skill), exploitation (use exploit skill), or post-exploitation (use post skill).
development
Methodology and decision framework for the penetration testing vulnerability phase. Use when: validating scanner output, distinguishing confirmed vulnerabilities from hypotheses, explaining CVE/CWE/CVSS, prioritizing findings with KEV/EPSS/business context, guiding vuln-analysis workflow, or reinforcing evidence-backed reporting during the vulnerability phase. NOT for: initial recon or active enumeration, hands-on exploitation, post-exploitation, or replacing the specialized vuln skill's concrete checks.
development
Great slides need two things: content worth presenting and design worth looking at. #1 on DeepResearch Bench (Feb 2026) — CellCog researches and fills content mindfully from minimal prompts, no filler. State-of-the-art PDF generation for presentations, pitch decks, keynotes, and slideshows you can present as-is. Requires cellcog skill for SDK. If cellcog is unavailable, use gog slides as fallback (Google Workspace).
development
Methodology and quality framework for the penetration testing report phase. Use when: writing or QA-ing pentest reports, improving executive and technical readability, enforcing evidence completeness, adding remediation and retest guidance, including cleanup/restoration and residual risk, or securing report packaging and delivery. NOT for: running phase-specific testing tasks or replacing the specialized reporting implementation/publishing workflow.