Agent skill

Sub-Agent Exploit-Run Delegation

by Encod3d-Sec in Encod3d-Sec/TORCH

Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

MITAuto-check: notesAgent Workflows

Install Sub-Agent Exploit-Run Delegation

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill delegate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH delegate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/workflow/delegate .claude/skills/delegate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
delegate
GitHub stars
329
Token cost
~1.6k tokens
SKILL.md length
861 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

  • Deciding whether a confirmed exploitation step is safe to hand to a cheaper sub-agent
  • SKILL.md covers When to delegate / when NOT, Model choice, The checklist (a delegation is… and False-root/hostname guardrail…, plus 4 more sections
  • Calls ssh and openssl
  • Writing a fully-specified checklist for a sub-agent to execute during an authorized test

What it does

This skill gives a main agent working an authorized penetration test or CTF a rule for when to delegate a step rather than do it directly. Delegation is reserved for a step that is fully specified and mechanical, such as compiling a known proof-of-concept or waiting on a fixed watch window, once a foothold and a working escalation vector are already confirmed; anything involving reconnaissance, judgment-heavy vector selection, or an unconfirmed vector stays with the main agent, since the skill frames that as a guess wearing a checklist rather than a real delegation.

A cheap model is the default choice for this kind of fully-specified run because the safety bar for executing a confirmed step is already cleared on an authorized engagement, with a stronger model reserved for genuinely judgment-heavy multi-step work. The skill explicitly forbids delegating discovery or judgment calls to a cheap model, warning that it can turn a mistaken query into a false negative that gets treated as fact, and it says any negative result a sub-agent reports should be re-verified before being accepted as a dead end.

Every delegation needs six filled-in slots, including the confirmed access or primitive already in hand, exact copy-paste commands with real values inlined rather than variables, tested egress and port constraints, and a non-negotiable guardrail the excerpt names but does not fully describe before being cut off.

When your agent uses it

  • Deciding whether a confirmed exploitation step is safe to hand to a cheaper sub-agent
  • Writing a fully-specified checklist for a sub-agent to execute during an authorized test
  • Choosing between a cheap and a stronger model for a pentest sub-task
  • Re-checking a sub-agent's negative result before treating it as a dead end

Example prompts

  • “We confirmed a working escalation vector. Delegate the compile-and-run step to a sub-agent.”
  • “Should this credential-decryption step go to a cheap model or stay with you?”
  • “The sub-agent reported this endpoint as empty. Re-verify that before we rule it out.”
  • “Write a fully-specified delegation checklist for this confirmed privilege-escalation step.”

Requirements

  • An authorized penetration test or CTF engagement with a confirmed foothold
  • A sub-agent runner capable of executing a scoped, mechanical task

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • ssh
    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use ssh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sub-Agent Exploit-Run Delegation loads about 1.6k tokens when it runs. Until then it costs about 119 tokens; SKILL.md has 861 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~119
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:88
    **(3) sudo `screen -r <name>` -> `Ctrl-A c` root**
  • NoteRuns commands with sudoSKILL.md:89
    Confirmed: `sudo -l` shows `screen` unrestricted and a root-owned session `<name>` is running. Run
  • NoteRuns commands with sudoSKILL.md:90
    `sudo screen -r <name>`, then send `Ctrl-A c` to spawn a new window inside the root screen. Report

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 861 words, ~1,583 tokens.

Download SKILL.mdSave it as .claude/skills/delegate/SKILL.md (or your agent's skills folder).
name
delegate
description
Autonomous sub-agent hand-off for a fiddly, fully-specified exploit-compile / escalation RUN - the main agent stays on strategy and the board while a cheap sub-agent runs an exact copy-paste checklist behind a false-root/hostname guardrail. Use for "delegate", "offload", "hand this to a sub-agent", "spin a haiku", or the moment a foothold plus a working escalation vector is identified. Main agent dispatches, waits (no parallel duplicate), integrates the result.

Delegate: sub-agent exploit-run

Hand a fiddly, fully-specified exploit-compile or escalation run to a cheap sub-agent so the main agent stays on strategy and the board.

When to delegate / when NOT

Delegate when a foothold plus a WORKING escalation vector is identified, or the step itself is a fiddly fully-specified multi-step compile/run: compile a C PoC, deliver and run an ELF, drive su/sudo/screen -r, msfvenom + multi/handler catch. Keep on the main agent: recon, judgement- heavy vector selection, anything not fully specified. An unconfirmed vector is not a delegation, it is a guess wearing a checklist.

Model choice

haiku is the DEFAULT for a fully-specified mechanical or wait-heavy run: compile-and-run a known exploit, deliver an ELF, decrypt a credential store, a pspy/tcpdump watch window, a fixed-payload flag-read. On CTF and RoE-approved pentests the safety bar for a cheap model executing an exploit is already cleared, so lean into haiku there and keep the main model on strategy. Step UP to sonnet only for a genuinely judgement-heavy multi-step run (a JS-heavy per-route-CSRF authed backend RCE).

NEVER delegate DISCOVERY or judgement to a cheap model: route/endpoint/token discovery, "is this surface empty or am I querying it wrong", vector selection. A cheap model hardens a wrong negative into a fact -- it reports "empty/dead" from a query mistake and you inherit it as a hard exclusion (a real miss: a delegated agent called a UCP voicemail "empty" because it hit the AJAX endpoint, not the dashboard widget that rendered the secret; that fossilized into a wrong "rabbit hole" and cost an hour+). If the run is not fully specified, it is not a delegation, it is a guess wearing a checklist, keep it on the main model. Re-verify any NEGATIVE a sub-agent returns before it becomes a Deadend.

The checklist (a delegation is only as good as its checklist)

Every delegation needs all six slots filled. Under-specify one and the sub-agent flails; that is the usual failure mode, not a weak sub-agent.

  • (a) confirmed access/primitive, spelled out; don't make the sub-agent rediscover it.
  • (b) exact copy-paste commands, real IPs/paths inline, no $VAR; the sub-agent cannot watch a live terminal to sanity-check a substitution.
  • (c) egress/port constraints, an egress-tested LPORT, not a guess at 4444.
  • (d) the false-root guardrail (next section), non-negotiable.
  • (e) fragile-box discipline if applicable: serial requests, long timeouts, no fuzzers.
  • (f) report-back contract: return the primitive/creds/flag plus evidence path; do not pivot further without the main agent.
  • (g) anti-give-up + no-guess: run the FULL specified window (a 5-minute pspy watch is 5 minutes, not 2); if blocked, report the RAW output/errors and STOP, never guess or substitute a value and never invent a result. A cheap model's instinct is to quit early and guess a token/flag, forbid both explicitly in the prompt.

False-root/hostname guardrail (MANDATORY every delegation)

A returned uid=0/root is trusted ONLY if hostname matches the target AND the expected uid holds. Otherwise the shell died back to the Kali box, which runs as root; $(...)/backticks there substitute LOCALLY, the false-RCE trap. The fix is re-pop, not celebrate. The sub-agent MUST report hostname alongside any id output, every time, no exceptions.

Show full SKILL.md (344 more words)Show less

Main-agent discipline

Keep driving the board while the sub-agent works. Dispatch ONE sub-agent at a time, serial; never duplicate its target in parallel. WAIT for completion before the next move. On return, persist the primitive/creds/flag to state.md/loot.md/Killchain.md before doing anything else.

Mechanism

Dispatch via the Agent tool: subagent_type general-purpose, model per the choice above, the checklist as the prompt, an explicit return/report contract written into the prompt itself. This skill's invocation IS the standing authorization to use the Agent tool mid-engagement; no separate approval needed.

Worked examples

Each uses placeholder tokens only.

(1) Catch a meterpreter as a service account Confirmed: RCE via the admin panel upload field on <target>. Egress-test the LPORT first (80/443 before 4444). Start multi/handler on the Kali VM, then deliver an inline base64 ELF payload through the panel RCE. Report back hostname + id + the session log path.

(2) ssh2john -> crack -> ssh-keygen -p strip -> SSH chain Confirmed: a private key at <path> protected by a passphrase. Run ssh2john <path> > <hash-file>, crack with the standard wordlist, then ssh-keygen -p -f <path> to strip the passphrase, then ssh -i <path> <user>@<target>. Report the cracked passphrase and the resulting shell's hostname + id.

(3) sudo screen -r <name> -> Ctrl-A c root Confirmed: sudo -l shows screen unrestricted and a root-owned session <name> is running. Run sudo screen -r <name>, then send Ctrl-A c to spawn a new window inside the root screen. Report hostname + id from inside that window before touching anything else; the guardrail applies here too.

(4) openssl-caps .so constructor root Confirmed: the openssl binary carries cap_setuid+ep. Compile a .so with a constructor that execs a shell, run it via openssl req -engine <path-to-so>, then confirm hostname + id inside the new shell before reporting root.

Once a working checklist and guardrail confirm a primitive, hand the box's actual next step to Skill(metasploit) when the run is msf-shaped (handler catch, module-driven exploit); this skill covers the delegation pattern itself, not the msf mechanics.

Client-data boundary

Worked examples use placeholders only; never put a real target IP, hostname, or credential into this skill file.

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/workflow/delegate of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Sub-Agent Exploit-Run Delegation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sub-Agent Exploit-Run Delegation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sub-Agent Exploit-Run Delegation this skillEncod3d-Sec/TORCH329—~1.6kAutomated safety check: NotesMIT
Dast Automationhardw00t/ai-security-arsenal104—~2.2kAutomated safety check: PassNone
Kantor Agenthumaedihume/kantor-agent100—~1kAutomated safety check: PassMIT
Agentic Tool Integrationsamugit83/redamon2.9k—~1.3kAutomated safety check: PassMIT
Reviewgetsentry/sentry-react-native1.8k—~1.9kAutomated safety check: PassMIT
Reviewgetsentry/sentry-dart873—~1.3kAutomated safety check: PassMIT

Similar skills

  • Dast Automation

    hardw00t/ai-security-arsenal

    Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling.

    104 GitHub stars~2.2k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Kantor Agent

    humaedihume/kantor-agent

    Jalankan "Kantor Agent" — kantor 3D (three.js) tanpa konfigurasi di http://127.0.0.1:8788/kerja yang menampilkan apa yang sedang dikerjakan Claude di project ini.

    100 GitHub stars~1k tokensUpdated 8 days ago
    Game DevelopmentAuto-check passed
  • Agentic Tool Integration

    samugit83/redamon

    Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…

    2.9k GitHub stars~1.3k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Review

    getsentry/sentry-react-native

    Official

    Three-axis review of the branch diff — Standards (this repo's documented standards + public API/bridge surface), Spec (the originating Linear/GitHub issue or PR), and Correctness (runtime bugs + the…

    1.8k GitHub stars~1.9k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Review

    getsentry/sentry-dart

    Official

    Three-axis review of the branch diff — Standards (this repo's documented standards + public API surface), Spec (the originating Linear issue / PR), and Correctness (runtime bugs + the SDK threat…

    873 GitHub stars~1.3k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Review Swarm

    Dimillian/Skills

    Parallel read-only multi-agent review of a current git diff or explicit file scope to find behavioral regressions, security or privacy risks, performance or reliability issues, and contract or test…

    4k GitHub starsUsed in 1 repo~1.6k tokens
    Agent WorkflowsAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Hunt Idor

    Encod3d-Sec/TORCH

    IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…

    329 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Sub-Agent Exploit-Run Delegation

What does Sub-Agent Exploit-Run Delegation do?

Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely. This skill gives a main agent working an authorized penetration test or CTF a rule for when to delegate a step rather than do it directly. Delegation is reserved for a step that is fully specified and mechanical, such as compiling a known proof-of-concept or waiting on a fixed watch window, once a foothold and a working escalation vector are already confirmed; anything involving reconnaissance, judgment-heavy vector selection, or an unconfirmed vector stays with the main agent, since the skill frames that as a guess wearing a checklist rather than a real delegation.

When should I use Sub-Agent Exploit-Run Delegation?

Sub-Agent Exploit-Run Delegation fits situations like: deciding whether a confirmed exploitation step is safe to hand to a cheaper sub-agent; writing a fully-specified checklist for a sub-agent to execute during an authorized test; choosing between a cheap and a stronger model for a pentest sub-task; re-checking a sub-agent's negative result before treating it as a dead end.

How do I install Sub-Agent Exploit-Run Delegation in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill delegate -a claude-code`. Or copy the skill folder (skills/workflow/delegate in Encod3d-Sec/TORCH) into .claude/skills/delegate in your project. Claude Code loads it when a task matches its description.

How do I install Sub-Agent Exploit-Run Delegation in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill delegate -a codex`. Or copy the skill folder (skills/workflow/delegate in Encod3d-Sec/TORCH) into .agents/skills/delegate in your project. Codex loads it when a task matches its description.

Can I use Sub-Agent Exploit-Run Delegation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill delegate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/delegate, .gemini/skills/delegate, .github/skills/delegate and .opencode/skills/delegate in your project.

What does Sub-Agent Exploit-Run Delegation need to run?

Going by SKILL.md and its folder, Sub-Agent Exploit-Run Delegation needs the command-line tools its instructions call (ssh and openssl). Our summary lists: An authorized penetration test or CTF engagement with a confirmed foothold; A sub-agent runner capable of executing a scoped, mechanical task.

Does Sub-Agent Exploit-Run Delegation access the network?

SKILL.md contains no URLs. Its commands use ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Sub-Agent Exploit-Run Delegation safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Sub-Agent Exploit-Run Delegation use?

Sub-Agent Exploit-Run Delegation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sub-Agent Exploit-Run Delegation use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sub-Agent Exploit-Run Delegation?

Skills that share tags, products or a category with Sub-Agent Exploit-Run Delegation: Dast Automation (hardw00t/ai-security-arsenal, 104 stars), Kantor Agent (humaedihume/kantor-agent, 100 stars), Agentic Tool Integration (samugit83/redamon, 2.9k stars) and Review (getsentry/sentry-react-native, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sub-Agent Exploit-Run Delegation?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.