external/trailofbits-skills-curated/plugins/planning-with-files/skills/planning-with-files/SKILL.md
Implements file-based planning for complex multi-step tasks. Creates task_plan.md, findings.md, and progress.md as persistent working memory. Use when starting tasks requiring >5 tool calls, multi-phase projects, research, or any work where losing track of goals and progress would be costly.
npx skillsauth add seikaikyo/dash-skills planning-with-filesInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use persistent markdown files as working memory on disk.
/plan or create manually from
templatestask_plan.md with goal, phases, and key questionsfindings.md for research and decisionsprogress.md for session loggingContext Window = RAM (volatile, limited)
Filesystem = Disk (persistent, unlimited)
Anything important gets written to disk.
After many tool calls, the original goal drifts out of the attention
window. Reading task_plan.md brings it back. This is the single
most important pattern in file-based planning.
| File | Purpose | When to Update |
|------|---------|----------------|
| task_plan.md | Phases, progress, decisions | After each phase completes |
| findings.md | Research, discoveries, decisions | After ANY discovery |
| progress.md | Session log, test results | Throughout the session |
All three files go in the project root, not the plugin directory.
Never start a complex task without task_plan.md. This is
non-negotiable. The plan is your persistent memory.
After every 2 search, browse, or read operations, immediately save
key findings to findings.md. Multimodal content (images, browser
results, PDF contents) does not persist in context -- capture it as
text before it is lost.
Before any major decision, re-read task_plan.md. This pushes
goals and context back into the recent attention window, counteracting
the "lost in the middle" effect that occurs after ~50 tool calls.
[Original goal -- far away in context, forgotten]
...many tool calls...
[Recently read task_plan.md -- gets ATTENTION]
→ Now make the decision with goals fresh in context
After completing any phase:
in_progress -> completeprogress.mdEvery error goes in task_plan.md. Include the attempt number and
resolution. This builds knowledge and prevents repeating failures.
## Errors Encountered
| Error | Attempt | Resolution |
|-------|---------|------------|
| FileNotFoundError | 1 | Created default config |
| API timeout | 2 | Added retry logic |
If an action failed, the next action must be different. Track what you tried and mutate the approach.
if action_failed:
next_action != same_action
ATTEMPT 1: Diagnose & Fix
-> Read error carefully
-> Identify root cause
-> Apply targeted fix
ATTEMPT 2: Alternative Approach
-> Same error? Try a different method
-> Different tool? Different library?
-> NEVER repeat the exact same failing action
ATTEMPT 3: Broader Rethink
-> Question assumptions
-> Search for solutions
-> Consider updating the plan
AFTER 3 FAILURES: Escalate to User
-> Explain what you tried (with attempt log)
-> Share the specific error
-> Ask for guidance
| Situation | Action | Reason | |-----------|--------|--------| | Just wrote a file | Don't read it | Content still in context | | Viewed image/PDF | Write findings NOW | Multimodal content doesn't persist | | Browser returned data | Write to file | Screenshots don't persist | | Starting new phase | Read plan/findings | Re-orient if context is stale | | Error occurred | Read relevant file | Need current state to fix | | Resuming after gap | Read all planning files | Recover full state |
If you can answer these from your planning files, context is solid:
| Question | Answer Source |
|----------|--------------|
| Where am I? | Current phase in task_plan.md |
| Where am I going? | Remaining phases |
| What's the goal? | Goal statement in plan |
| What have I learned? | findings.md |
| What have I done? | progress.md |
| Don't | Do Instead | |-------|------------| | State goals once and forget | Re-read plan before decisions | | Hide errors and retry silently | Log every error to plan file | | Stuff everything in context | Store large content in files | | Start executing immediately | Create plan file FIRST | | Repeat failed actions | Track attempts, mutate approach | | Create files in plugin directory | Create files in project root |
tools
Conduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of processing, lawful basis validation, data subject rights implementation, Data Protection Impact Assessments (DPIAs) under Article 35, breach notification procedures, international transfer safeguards (SCCs, adequacy decisions), and technical/organizational measures under Article 32. Use when processing personal data of EU residents, preparing for supervisory authority audits, implementing privacy-by-design for new systems, scoping compliance gaps for M&A due diligence, assessing third-party processors, or responding to data subject access requests at scale. Incorporates 2026 guidance from ICO, EDPB, and post-Data (Use and Access) Act 2025 UK-GDPR considerations. Do not use for implementing specific Article 32 controls — use implementing-gdpr-data-protection-controls; or for DSAR automation — use implementing-gdpr-data-subject-access-request.
tools
Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into Timeline Explorer for analysis. Use during DFIR/incident-response investigations, after triage collection (e.g. with KAPE), to establish program execution, file/folder access, and persistence evidence from acquired forensic images.
development
Build automated multi-turn adversarial attacks against conversational LLM targets using Microsoft PyRIT's RedTeamingOrchestrator, CrescendoOrchestrator (gradual escalation), and TreeOfAttacksWithPruningOrchestrator (adaptive branching), with scorer feedback loops and persisted conversation memory. Use when single-shot LLM scanning is insufficient and you need multi-turn, scorer-driven AI red-team campaigns against a chatbot or agent.
testing
Stand up MISP, enable and cache curated threat feeds (CIRCL, abuse.ch, Feodo Tracker), apply warninglists to suppress false positives, query indicators with PyMISP, and export attributes as auto-generated Suricata/Sigma/Wazuh detection rules. Use when maturing a MISP instance to actively drive detection, curating threat feeds with quality controls, or automating IOC-to-detection pipelines for the SIEM/IDS.