Agent skill

Disclosure

by Encod3d-Sec in Encod3d-Sec/TORCH

Drive responsible disclosure of a proven finding to a CVE. An agent skill from Encod3d-Sec/TORCH.

MITAuto-check passedSecurity

Install Disclosure

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill disclosure -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH disclosure --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/disclosure .claude/skills/disclosure && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
disclosure
GitHub stars
329
Token cost
~686 tokens
SKILL.md length
314 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Drive responsible disclosure of a proven finding to a CVE. An agent skill from Encod3d-Sec/TORCH.

  • Works in 6 steps: Package the report from the finding:… → Find the contact (in order):… → Report privately over that channel;… → …
  • Report this to the vendor
  • SKILL.md covers Gate (READ FIRST), Procedure, Output and Wiki feedback
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Disclosure is an agent skill from Encod3d-Sec/TORCH. Drive responsible disclosure of a proven finding to a CVE. Package the report, find the vendor contact, report privately, coordinate a timeline, request the CVE (vendor CNA / GitHub / MITRE), and publish an advisory. Closes the research loop. Triggers - "disclose", "request a cve", "report this to the vendor".

Its SKILL.md is about 690 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning. It works with GitHub. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Report this to the vendor
  • Tasks that involve Vulnerability scanning

Example prompts

  • “disclose”
  • “request a cve”
  • “report this to the vendor”
  • “/disclosure”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Package the report from the finding: title, affected + fixed/tested versions, CWE class, CVSS vector + score, clear repro steps, minimal…
  2. Find the contact (in order): /.well-known/security.txt, SECURITY.md, security@, vendor PSIRT, a bug-bounty platform if they run one…
  3. Report privately over that channel; PGP-encrypt if a key is published. Professional, specific, non-extortive. Offer to validate the fix.
  4. Coordinate a timeline - propose ~90 days; track it; escalate to CERT/CC if the vendor goes dark past the deadline.
  5. Request the CVE: vendor CNA assigns it; for OSS open a GitHub Security Advisory (GitHub issues the CVE); otherwise MITRE CVE request form…
  6. Publish the advisory after fix/deadline: CVE ID, affected/fixed versions, CWE, CVSS, description, PoC, impact, remediation, timeline…

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Disclosure loads about 686 tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 314 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~81
When it runs · the whole SKILL.md, loaded when a task matches
~686

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 314 words, ~686 tokens.

Download SKILL.mdSave it as .claude/skills/disclosure/SKILL.md (or your agent's skills folder).
name
disclosure
description
Drive responsible disclosure of a proven finding to a CVE. Package the report, find the vendor contact, report privately, coordinate a timeline, request the CVE (vendor CNA / GitHub / MITRE), and publish an advisory. Closes the research loop. Triggers - "disclose", "request a cve", "report this to the vendor".

Disclosure: Finding -> CVE

Turn a proven, novel vulnerability into a coordinated disclosure and a published CVE. Pairs with the research skill (a finding in findings.md) or an engagement FIND. Read [[responsible-disclosure]] first.

Gate (READ FIRST)

  • The finding must be proven + reproducible (minimal PoC, affected versions, impact) and novelty-checked (not an existing CVE). If not, go back to the research skill.
  • Confirm you are authorised / in safe-harbor for the target. No authorization -> do not proceed (CFAA / Computer Misuse Act). Research on public software you can lawfully analyze is fine; testing live third-party systems needs permission.

Procedure

  1. Package the report from the finding: title, affected + fixed/tested versions, CWE class, CVSS vector + score, clear repro steps, minimal PoC, impact, suggested remediation, your contact. Redact any real data.
  2. Find the contact (in order): /.well-known/security.txt, SECURITY.md, security@<vendor>, vendor PSIRT, a bug-bounty platform if they run one, GitHub private vulnerability reporting for OSS, else CERT/CC.
  3. Report privately over that channel; PGP-encrypt if a key is published. Professional, specific, non-extortive. Offer to validate the fix.
  4. Coordinate a timeline - propose ~90 days; track it; escalate to CERT/CC if the vendor goes dark past the deadline.
  5. Request the CVE: vendor CNA assigns it; for OSS open a GitHub Security Advisory (GitHub issues the CVE); otherwise MITRE CVE request form (CNA of last resort). Supply product, versions, CWE, impact, reference.
  6. Publish the advisory after fix/deadline: CVE ID, affected/fixed versions, CWE, CVSS, description, PoC, impact, remediation, timeline, credit. Mirror to the researcher's blog/GitHub for the portfolio.

Output

  • A ready-to-send disclosure report (draft) and a public advisory (draft) saved under the project: raw/research/<project>/advisory.md (and the contact + timeline tracked in findings.md).
  • Update the finding status: candidate -> reported -> CVE-<id> -> published.

Wiki feedback

Reusable disclosure lesson (vendor process quirk, CNA tip) -> update [[responsible-disclosure]]. The vuln technique itself -> the matching wiki/techniques/ page via research-ingest.

Report: report + advisory drafts, contact channel, and the disclosure timeline.

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/disclosure of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Disclosure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Disclosure compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Disclosure this skillEncod3d-Sec/TORCH329—~686Automated safety check: PassMIT
Security AdvisoryMidnightBSD/src114—~2.2kAutomated safety check: PassCustom licence
Security Vulnerability Analysiseclipse-ankaios/ankaios125—~1.5kAutomated safety check: PassApache-2.0
Warp Vulnerability Triagewarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0
Cve Doctorgetlago/lago-front163—~2.9kAutomated safety check: PassMIT
Deal With Security Advisorypaperclipai/paperclip99k—~2kAutomated safety check: PassMIT

Similar skills

  • Security Advisory

    MidnightBSD/src

    Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING…

    114 GitHub stars~2.2k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Security Vulnerability Analysis

    eclipse-ankaios/ankaios

    Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.

    125 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed
  • Cve Doctor

    getlago/lago-front

    Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix.

    163 GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Deal With Security Advisory

    paperclipai/paperclip

    Handle confidential GitHub Security Advisory response for Paperclip.

    99k GitHub stars~2k tokensUpdated today
    SecurityAuto-check passed
  • Snapshot

    boostsecurityio/poutine

    Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

    523 GitHub stars~214 tokensUpdated yesterday
    SecurityAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Disclosure

What does Disclosure do?

Drive responsible disclosure of a proven finding to a CVE. An agent skill from Encod3d-Sec/TORCH. Disclosure is an agent skill from Encod3d-Sec/TORCH. Drive responsible disclosure of a proven finding to a CVE.

When should I use Disclosure?

Disclosure fits situations like: report this to the vendor; tasks that involve Vulnerability scanning.

How do I install Disclosure in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill disclosure -a claude-code`. Or copy the skill folder (skills/disclosure in Encod3d-Sec/TORCH) into .claude/skills/disclosure in your project. Claude Code loads it when a task matches its description.

How do I install Disclosure in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill disclosure -a codex`. Or copy the skill folder (skills/disclosure in Encod3d-Sec/TORCH) into .agents/skills/disclosure in your project. Codex loads it when a task matches its description.

Can I use Disclosure in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill disclosure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/disclosure, .gemini/skills/disclosure, .github/skills/disclosure and .opencode/skills/disclosure in your project.

What does Disclosure need to run?

SKILL.md names no scripts, command-line tools or credentials: Disclosure is instructions for the agent only.

Does Disclosure access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Disclosure safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Disclosure use?

Disclosure is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Disclosure use?

About 686 tokens (SKILL.md is roughly 2.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Disclosure?

Skills that share tags, products or a category with Disclosure: Security Advisory (MidnightBSD/src, 114 stars), Security Vulnerability Analysis (eclipse-ankaios/ankaios, 125 stars), Warp Vulnerability Triage (warpdotdev/warp, 65k stars) and Cve Doctor (getlago/lago-front, 163 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Disclosure?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.