npx skills add smithery/nicobailon --skill coordination
transilienceai/communitytools
coordination
Pentest coordination — orchestrates executor and validator agents with context-controlled spawning. Entry point for all engagements.
Installation
npx skills add transilienceai/communitytools --skill coordination
Similar popular skills
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
Browser automation CLI for AI agents. Use when the user needs to interact with websites, includ…
810.4K installsConfigure Azure API Management as an AI Gateway for AI models, MCP tools, and agents. WHEN: sem…
566.3K installsAzure VM/VMSS router. WHEN: create / provision / deploy / spin-up VM, recommend VM size, compar…
510K installsPostgres best practices maintained by Supabase, for Postgres running anywhere. Load this skill …
391.6K installsPrisma ORM CLI commands reference covering init, generate, migrate, db, dev, complete, studio, …
267K installsUse when doing ANY task involving Supabase. Triggers: Supabase products (Database, Auth, Edge F…
263K installsAlso in this package
Other skills from transilienceai/communitytools · top by installs.
npx skills add transilienceai/communitytools
More details
Agent compatibility
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Also listed on
Alternate registries and mirrors of this skill.
Repository health
main
Package contents
Files included with this skill beyond the listing page.
-
skill md
SKILL.md7,262 B -
docs
SUMMARY.md154 B
History
- First seen on skills.sh
- First recorded snapshot · 123 installs
SKILL.md
Coordination
Runs as a spawned subagent (one per target). Within its own context, the coordinator holds engagement state inline — it does not delegate its thinking to further sub-subagents. Thinks before every action.
The parent orchestrator (main session) must not execute this workflow inline. If you find yourself doing P1-P5 in the main session, you skipped the spawn step in skills/hackthebox/SKILL.md (or the relevant platform skill) and the bookkeeping discipline is silently disabled.
Principle (Rule 0)
Source code first. Read all accessible source — application code, config, scripts, share contents — before any executor batch. Every answer is in the data you already have. Guessing without reading is the most common failure mode.
Workflow
P0: Ingest scope
↓
P1: Recon + read source code → write attack-chain.md → run preflight-checklist
↓
┌→ P2: Think — read chain + experiments.md, write 3 hypotheses (≥1 [wildcard]), pick 1-2 to test
│ P2b: Research (conditional) — see reference/creative-research.md
│ P3: Execute — spawn 1-2 executors with CHAIN_CONTEXT [+ RESEARCH_BRIEF]
│ P4: Integrate — materialize each candidate; **validate it now** (interleaved, strict per-finding,
│ fresh blind agents) → CONFIRMED | REJECTED | CURE→re-validate | DROPPED; update chain, revise theory
│ Coverage flips only on VALID (coverage-by-VALID); REJECTED/DROPPED classes stay pending → keep searching
│ No progress 1 batch → consider P2b · goal_attempts ≥ 3 on any conceptual goal → P4b
└─ loop (max 30 experiments; mandatory skeptic at experiments 5, 15, 25)
P4b: Reset — re-read all recon + source + chain. Creative Research (mandatory). Fresh theory.
P5: Engagement-thoroughness validation + Report (validated/ = VALID/REPAIRED only; drop-entirely, no gaps section)
Steps
- Recon + Source Code — read all accessible code (see
formats/reconnaissance.md). Run pre-flight checklist (reference/preflight-checklist.md). - Think — write 3 hypotheses to
attack-chain.md, ≥1 tagged[wildcard]. Pick 1-2 to spawn. - Test — 1-2 executors per batch, integrate before next.
- Validate (interleaved) — validate each candidate the instant INTEGRATE materializes it, on fresh blind agents (strict per-finding cure/drop loop → CONFIRMED | REJECTED | CURE | DROPPED); at loop end run the engagement-thoroughness validator (see
reference/validator-role.md). - Report — the
VALID/REPAIREDfindings in{OUTPUT_DIR}/artifacts/validated/(all of them, by construction) → Transilience PDF viaformats/transilience-report-style/SKILL.md.
attack-chain.md
{OUTPUT_DIR}/attack-chain.md. Updated every batch. Sections: services, surface, theory (3 hypotheses + chosen), tested, next. Bullets, max 50 lines, prune old items to one-liners.
Bookkeeping
experiments.md ledger, tools/ logs, EXPERIMENT_ID injection, conceptual-goal counting — see reference/bookkeeping.md.
Creative Research (P2b)
Triggers: P4b reset (mandatory), goal_attempts ≥ 3 on any goal, novel error class, source code unreadable, every executor returned negative, no hypothesis at P2, no progress for 1 batch. See reference/creative-research.md. Most batches skip P2b.
Spawning
See reference/spawning-recipes.md for copy-paste-ready spawn patterns per role. Context contracts in reference/context-injection.md. Role boundaries in reference/role-matrix.md.
Roles
| Role | File | Context | When |
|---|---|---|---|
| Executor (explore) | reference/executor-role.md |
Full chain + skills | Recon / breadth |
| Executor (exploit) | reference/executor-role.md |
Full chain + skills + scenarios | Confirmed theory |
| Skeptic | reference/skeptic-role.md |
experiments.md + recon (no chain) | Mandatory at experiments 5, 15, 25 |
| Validator (finding) | reference/validator-role.md |
Evidence only (blind) | Interleaved — each candidate the instant it's materialized; fresh each cure round |
| Executor (cure) | reference/executor-role.md |
Only named failedchecks + missingevidence (no theory) |
On a DEMOTED verdict, before re-validation |
| Validator (engagement) | reference/validator-role.md |
OUTPUT_DIR only (blind) | Once at loop end |
Rules
- Autonomous. Coordinator MUST NOT call
AskUserQuestion. If a credential is missing, runpython3 tools/env-reader.py; if it returns NOT_SET, terminate withstatus=BLOCKEDand emit a clear blocker. Asking is the parent orchestrator's job. - Think before acting. Write 3 hypotheses (≥1 wildcard) to attack-chain.md before every batch. Record rejected ones — they are the search tree.
- Max 1-2 executors per batch. Recon can use more.
- Pass chain context + specific PATT_URL to executors. Not the full PATT map.
- 30-experiment cap.
- goal_attempts ≥ 3 on a conceptual goal → P4b reset. Count by goal, not literal technique string. Five PKINIT cert variants chasing "use this cert to authenticate" = five strikes against one goal. See
reference/bookkeeping.mdfor the goal column. - Mandatory skeptic at experiments 5, 15, 25 (see
reference/skeptic-role.md). - All output to OUTPUT_DIR.
- Sequential flag progression in multi-flag engagements. User-foothold first; root path usually flows from there.
- No partial completion as a success state. A multi-flag engagement is incomplete until every flag submits.
status=FAILED_partialis a temporary marker, never a final outcome. - Phase 3 (skill-update + Slack + queue) is parent-orchestrator only. Coordinator emits PHASE3_SUMMARY and exits.
- Source for library internals. Before writing Python against any library API (Impacket, ldap3, pyasn1), read the source. Prefer CLI tools (secretsdump.py, ticketer.py, getST.py).
- Background command discipline. State the specific result a tunnel/relay/listener will produce before spawning.
- Report gate. Validated findings exist → Transilience PDF report required. Read
formats/transilience-report-style/pentest-report.md. - Validation completeness. After validators run, every validated finding has
evidence/validation/validation-summary.md. Flag any without proof.
Token Discipline
- Internal output (chain, logs, reports): bullets, not prose.
- Executor prompts: 1-2 relevant skill files + the specific PATT_URL.
- attack-chain.md max 50 lines; bookkeeping max 10% of mission tokens.
- User-facing output (reports, summaries): detailed.
References
reference/principles.md · reference/preflight-checklist.md · reference/role-matrix.md · reference/bookkeeping.md · reference/spawning-recipes.md · reference/context-injection.md · reference/creative-research.md · reference/executor-role.md · reference/skeptic-role.md · reference/validator-role.md · reference/VALIDATION.md · reference/ATTACKINDEX.md · reference/OUTPUTSTRUCTURE.md · reference/GIT_CONVENTIONS.md · formats/INDEX.md