$npx -y skills add hypnguyen1209/offensive-claude --skill engagement-flowUse when starting, planning, or running a multi-phase pentest or red-team engagement — to sequence the Cyber Kill Chain phases with quality gates instead of jumping straight to exploitation
| 1 | # Engagement Flow |
| 2 | |
| 3 | ## Overview |
| 4 | |
| 5 | A pentest/red-team engagement is a **phased pipeline with gates**, not a pile of techniques run |
| 6 | ad hoc. This skill sequences the 9-phase Lockheed Martin Cyber Kill Chain and routes each phase to |
| 7 | its commands, domain skills, and discipline checks. It is the offensive analog of |
| 8 | brainstorming → writing-plans → executing-plans: scope the work, plan it, then execute phase by phase. |
| 9 | |
| 10 | Don't jump to exploitation. Earlier phases earn the access that later phases need, and each gate |
| 11 | keeps quality high before you advance. |
| 12 | |
| 13 | ## The pipeline |
| 14 | |
| 15 | ```dot |
| 16 | digraph killchain { |
| 17 | rankdir=LR; |
| 18 | scope -> recon -> weaponize -> deliver -> exploit -> install -> c2 -> actions -> report; |
| 19 | scope [label="0 SCOPE"]; recon [label="1 RECON"]; weaponize [label="2 WEAPONIZE"]; |
| 20 | deliver [label="3 DELIVER"]; exploit [label="4 EXPLOIT"]; install [label="5 INSTALL"]; |
| 21 | c2 [label="6 C2"]; actions [label="7 ACTIONS"]; report [label="8 REPORT"]; |
| 22 | } |
| 23 | ``` |
| 24 | |
| 25 | Each transition requires a **gate** (`/engage.gate`): required artifacts present, findings carry |
| 26 | CWE+CVSS+ATT&CK+evidence, and the automated checks pass. Gate FAIL → fix the gap before advancing. |
| 27 | |
| 28 | ## How to run it |
| 29 | |
| 30 | 1. Pick the workflow preset for the engagement type (web-app, network, red-team, cloud, mobile, |
| 31 | ad-domain, bug-bounty) and drive phases with the `/engage.*` commands. |
| 32 | 2. **Phase 0 (scope):** emit `.engage/scope/scope.json`. **REQUIRED:** scope-discipline. |
| 33 | 3. **Phases 1-7:** before any target interaction → scope-discipline; before any outward action → |
| 34 | opsec-discipline; invoke the matching domain skill for the technique. |
| 35 | 4. **Recall prior intel:** at recon/weaponize, `/engage.memory recall` to start from what worked. |
| 36 | 5. **Findings:** **REQUIRED:** finding-discipline — nothing is `[CONFIRMED]` without proof. |
| 37 | 6. **Phase 8 (report):** record confirmed findings to engagement-memory; generate the report. |
| 38 | 7. **Optional autopilot:** `engine/engine.py` runs the phases under a budget/loop/trace with `--resume` |
| 39 | (`/engage.pickup`); offensive actions stay operator-gated. |
| 40 | |
| 41 | ## Red Flags — STOP, back up a phase |
| 42 | |
| 43 | - "Let me just start exploiting" (no scope.json / no recon → back to phase 0/1) |
| 44 | - "Skip the gate, I'll document later" (gates exist so the report is complete and findings are real) |
| 45 | - "Recon is done, I didn't check prior intel" (run `/engage.memory recall`) |
| 46 | |
| 47 | ## Quick reference |
| 48 | |
| 49 | | Phase | Command | Discipline / tooling | |
| 50 | |-------|---------|----------------------| |
| 51 | | Scope | `/engage.scope` | scope-discipline → `scope.json` | |
| 52 | | Recon | `/engage.recon` | scope-discipline; `/engage.memory recall` | |
| 53 | | Exploit | `/engage.exploit` | opsec-discipline; finding-discipline | |
| 54 | | Actions | `/engage.actions` | action_guard gate; opsec-discipline | |
| 55 | | Report | `/engage.report` | finding-discipline; record to memory | |
| 56 | | Gate / resume | `/engage.gate`, `/engage.pickup` | automated checks; engine trace | |