Agent skill

Campaign Workflow Health Check

by Encod3d-Sec in Encod3d-Sec/TORCH

Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

MITAuto-check passedSecurity

Install Campaign Workflow Health Check

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill campaign-health -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH campaign-health --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/workflow/campaign-health .claude/skills/campaign-health && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
campaign-health
GitHub stars
329
Token cost
~611 tokens
SKILL.md length
220 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

  • Setting up the workflow driver on a new machine
  • SKILL.md covers Run it, What it checks and Fixing what it reports
  • Calls python3 and bash
  • Verifying everything after a vault sync

What it does

The vault syncs between machines but `~/.claude`, which holds hook registration, skill symlinks and dependencies, does not, so a working setup on one machine says nothing about another. This skill runs `python3 scripts/campaign-doctor.py`, which shows only warnings and failures by default and everything with `--verbose`, and exits 0 when all is green and 1 when at least one check fails.

Three groups of checks run. Vault content confirms the driver scripts exist, campaign JSON is valid, each type's approach is wired into the playbook and coverage files, two hook edits are present, all 69 tool pages carry `phase:` and the tool index resolves an invocation for every tool. Machine wiring confirms the three workflow skills are symlinked into `~/.claude/skills`, hooks are registered and `_engagement` imports. A live smoke test runs init, board and next on a throwaway fixture copy. Warnings usually name a setup script to run, and failures call for re-pulling the vault or rerunning the tool phase backfill.

When your agent uses it

  • Setting up the workflow driver on a new machine
  • Verifying everything after a vault sync
  • Diagnosing why the workflow board is not working

Example prompts

  • “Run campaign health and show me every check.”
  • “Is the workflow set up on this machine? Check hooks and scripts.”
  • “Why is the board not working after I synced the vault?”

Requirements

  • Python 3
  • The workflow vault with its scripts and setup folder

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Campaign Workflow Health Check loads about 611 tokens when it runs. Until then it costs about 166 tokens; SKILL.md has 220 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~166
When it runs · the whole SKILL.md, loaded when a task matches
~611

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 220 words, ~611 tokens.

Download SKILL.mdSave it as .claude/skills/campaign-health/SKILL.md (or your agent's skills folder).
name
campaign-health
description
Health check for the bb/pt/ctf workflow driver subsystem - verifies everything is in place so every machine runs the same. Checks vault-content consistency (scripts present, JSON valid, routing wired, all 69 tool pages carry phase:, the tool index resolves, the hook edits are in place) AND per-machine wiring (the three workflow skills symlinked, hooks registered, imports work), then runs a live init->board->next smoke test. Use when setting up the workflow on a new machine, after a vault sync, when the driver misbehaves, or on "bb-health", "campaign health", "is the workflow set up", "check hooks and scripts", "why is the board not working".

campaign-health

The vault syncs across machines; ~/.claude (hook registration, skill symlinks, deps) does not. So "it works here" does not mean "it works there". This skill confirms both halves before you rely on bb-workflow / pt-workflow / ctf-workflow on this machine.

Run it

python3 scripts/campaign-doctor.py            # summary (only WARN/FAIL shown)
python3 scripts/campaign-doctor.py --verbose   # every check

Exit 0 = all green. Exit 1 = at least one FAIL; the driver will not run correctly here until fixed.

What it checks

  • A. vault content - the driver's scripts exist, every campaign JSON is valid, each type's approach exists in playbook.json and coverage-classes.json, the two hook edits (recon-capture emits spec['tools'], tool-telemetry logs binaries) are present, all 69 wiki/tools/ pages carry phase:, and campaign.tool_index() resolves an invocation for every tool.
  • B. machine wiring - the three workflow skills are authored and symlinked into ~/.claude/skills, hooks are registered (via check-hooks.py), and _engagement imports.
  • C. live smoke test - init -> board -> next against a throwaway copy of the fixture, asserting the board writes rows and next withholds the exploit at G1.

Fixing what it reports

  • WARN (machine wiring) - usually one setup script the doctor names: bash setup/install-skills.sh (skills) or bash setup/install-hooks.sh (hooks).
  • FAIL (vault content) - a stale sync or a partial edit. Re-pull the vault; if a tool page lost its phase:, re-run python3 scripts/tool-phase-backfill.py --write.

Run this first on any new machine, and after every vault sync, so all machines run the same driver.

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/workflow/campaign-health of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Campaign Workflow Health Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Campaign Workflow Health Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Campaign Workflow Health Check this skillEncod3d-Sec/TORCH329—~611Automated safety check: PassMIT
Metabigor OSINT Reconj3ssie/metabigor1.9k—~2.4kAutomated safety check: PassMIT
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT
Web3 Bug Bounty AI Toolstradecatlabs/vibe-coding-cn17k2 repos~3.9kAutomated safety check: WarnMIT
Add Partial Reconsamugit83/redamon3k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.9k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Web3 Bug Bounty AI Tools

    tradecatlabs/vibe-coding-cn

    A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

    17k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check: warnings
  • Add Partial Recon

    samugit83/redamon

    Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.

    3k GitHub stars~1.1k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • External Recon Playbook

    PentesterFlow/agent

    Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology.

    1.4k GitHub stars~1.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Hunt Core

    Encod3d-Sec/TORCH

    Shared discipline for every hunt- skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop…

    329 GitHub stars~3.5k tokensUpdated 1 mo ago
    Auto-check: notes

Questions about Campaign Workflow Health Check

What does Campaign Workflow Health Check do?

Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures. claude`, which holds hook registration, skill symlinks and dependencies, does not, so a working setup on one machine says nothing about another.py`, which shows only warnings and failures by default and everything with `--verbose`, and exits 0 when all is green and 1 when at least one check fails.

When should I use Campaign Workflow Health Check?

Campaign Workflow Health Check fits situations like: setting up the workflow driver on a new machine; verifying everything after a vault sync; diagnosing why the workflow board is not working.

How do I install Campaign Workflow Health Check in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill campaign-health -a claude-code`. Or copy the skill folder (skills/workflow/campaign-health in Encod3d-Sec/TORCH) into .claude/skills/campaign-health in your project. Claude Code loads it when a task matches its description.

How do I install Campaign Workflow Health Check in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill campaign-health -a codex`. Or copy the skill folder (skills/workflow/campaign-health in Encod3d-Sec/TORCH) into .agents/skills/campaign-health in your project. Codex loads it when a task matches its description.

Can I use Campaign Workflow Health Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill campaign-health -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/campaign-health, .gemini/skills/campaign-health, .github/skills/campaign-health and .opencode/skills/campaign-health in your project.

What does Campaign Workflow Health Check need to run?

Going by SKILL.md and its folder, Campaign Workflow Health Check needs the command-line tools its instructions call (python3 and bash). Our summary lists: Python 3; The workflow vault with its scripts and setup folder.

Does Campaign Workflow Health Check access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Campaign Workflow Health Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Campaign Workflow Health Check use?

Campaign Workflow Health Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Campaign Workflow Health Check use?

About 611 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Campaign Workflow Health Check?

Skills that share tags, products or a category with Campaign Workflow Health Check: Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars), Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Client Request Signature Reversal (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Web3 Bug Bounty AI Tools (tradecatlabs/vibe-coding-cn, 17k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Campaign Workflow Health Check?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.