Agent skill

Research

by Encod3d-Sec in Encod3d-Sec/TORCH

Vulnerability-research loop toward a novel CVE. An agent skill from Encod3d-Sec/TORCH.

MITAuto-check passedSecurity

Install Research

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill research -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH research --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/research .claude/skills/research && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
research
GitHub stars
329
Token cost
~1.8k tokens
SKILL.md length
788 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Vulnerability-research loop toward a novel CVE. An agent skill from Encod3d-Sec/TORCH.

  • Works in 9 steps: Setup (once per target) → State-first (EVERY iteration, MANDATORY) → Attack-surface map (surface.md) → …
  • Analyze this binary/library
  • SKILL.md covers 0. Setup (once per target), 1. State-first (EVERY…, 2. Attack-surface map… and 3. Hypothesize (ranked, in…, plus 7 more sections
  • Calls bash, python3 and git

What it does

Research is an agent skill from Encod3d-Sec/TORCH. Vulnerability-research loop toward a novel CVE. Target triage - attack-surface map - ranked hypotheses - investigate (RE / fuzz / audit) - a finding deepens the loop, a dead-end pivots to a new approach. Uses the full wiki + hunt skillset. Scaffolds and persists state under raw/research/<project/. Triggers - "research", "find a cve", "analyze this binary/library", "audit this code for vulns".

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning, Threat modeling and Creative writing and fiction. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Analyze this binary/library
  • Audit this code for vulns

Example prompts

  • “research”
  • “find a cve”
  • “analyze this binary/library”
  • “/research”

Requirements

  • Python 3

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Setup (once per target)
  2. State-first (EVERY iteration, MANDATORY)
  3. Attack-surface map (surface.md)
  4. Hypothesize (ranked, in loop.md)
  5. Investigate (loop body)
  6. Evaluate the result
  7. Deepen the finding (the loop continues from here)
  8. Prove + novelty-check
  9. Write up (CVE-grade)

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash
    • python3
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Research loads about 1.8k tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 788 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 788 words, ~1,846 tokens.

Download SKILL.mdSave it as .claude/skills/research/SKILL.md (or your agent's skills folder).
name
research
description
Vulnerability-research loop toward a novel CVE. Target triage -> attack-surface map -> ranked hypotheses -> investigate (RE / fuzz / audit) -> a finding deepens the loop, a dead-end pivots to a new approach. Uses the full wiki + hunt skillset. Scaffolds and persists state under raw/research/<project>/. Triggers - "research", "find a cve", "analyze this binary/library", "audit this code for vulns".

Research: CVE Discovery Loop

Find and prove one novel vulnerability in a target (binary, library, web app/API, firmware, protocol, or source repo). The loop is persistent, resumable, and anti-loop: findings deepen it, dead-ends pivot it, and every step is driven by the knowledge base.

This skill is the research analog of the engagement framework: raw/research/<project>/ is to research what targets/<eng>/ is to an engagement.


0. Setup (once per target)

  1. Identify target type + version + source. Get the code/binary: repos via WSL clone (wsl -d kali-linux -u kali -- git clone <url> /home/kali/<name>), releases by download.
  2. Scaffold: bash setup/new-research.sh <project_name> -> raw/research/<project>/{target,surface,findings,deadends,loop}.md + poc/ (also sets it active in raw/research/active.md, so SessionStart surfaces its status).
  3. Build/run it where possible - a runnable target unlocks dynamic testing + fuzzing.
  4. Fill target.md: what it is, version, language, build/run commands, trust boundaries.

1. State-first (EVERY iteration, MANDATORY)

Read raw/research/<project>/{loop.md, deadends.md, findings.md} before acting. Never re-run a logged dead-end without new input. Resume from the last iteration. This is the anti-loop rule - the same discipline engagements use. Run python3 scripts/research_status.py for the current phase + ranked next move (also auto-surfaced at SessionStart from raw/research/active.md).

2. Attack-surface map (surface.md)

qmd_query the target's tech/language/framework first, then map by type:

Target typeFirst movesKnowledge base
binary / executablechecksec, strings, RE entry + parsers, identify input handling[[reverse-engineering]] [[ghidra]] [[radare2]] [[binary-exploitation]] [[memory-safety-bugs]] [[fuzzing]] [[aflplusplus]] [[gdb-gef]]
C/C++ librarygrep dangerous APIs, build a fuzz harness, map public API[[memory-safety-bugs]] [[fuzzing]] [[libfuzzer]] [[aflplusplus]] [[static-code-analysis]] [[semgrep]] [[codeql]]
web app / APImap routes, auth, sinks; diff vs known framework CVEsweb hunt skills (sqli/idor/auth/injection/deser/ssrf/upload) + [[source-audit-checklist]] [[static-code-analysis]]
firmwarebinwalk -Me, extract rootfs, then treat components as binary/web[[firmware-hardware]] [[binwalk]]
protocol / network serviceRE the parser/state machine, fuzz the wire format[[protocol-attacks]] [[fuzzing]] [[aflplusplus]] [[reverse-engineering]] [[ghidra]]
source repo (any lang)audit + dependency CVE review + secret/history scan[[source-audit-checklist]] [[static-code-analysis]] [[semgrep]] [[codeql]] [[trivy]] [[secret-hunting]] [[git-exposure]] + the matching vuln-class page

Record in surface.md: entry points (attacker-controlled input), parsers/deserializers, dangerous sinks, privileged ops, dependencies with CVE history.

3. Hypothesize (ranked, in loop.md)

From the surface + knowledge base, write hypotheses as <input/location> + <bug class> = <expected primitive>. Rank by: reachable from an attacker boundary, attacker-controlled, lands in a dangerous sink, historically buggy area, weak/old dependency. Pick the highest-value untested hypothesis (skip anything in deadends.md).

4. Investigate (loop body)

Apply the matching technique + hunt skill + tool to the chosen hypothesis. Bound the effort up front (e.g. fuzz N hours / M execs; audit this component once; sweep this payload class once).

  • memory-safety: audit sinks with [[memory-safety-bugs]], then build/point a fuzzer at the parser ([[aflplusplus]] / [[libfuzzer]], always with a sanitizer), triage crashes ([[crash-analysis]]), RE the root cause in [[ghidra]].
  • web/logic (source available): work the [[source-audit-checklist]] (sources -> sinks), then invoke the matching hunt-* skill (auth/idor/injection/deser/ssrf/upload/bizlogic/smuggling) to confirm with the payload arsenal.
  • injection/parse: malformed/oversized/encoded inputs at each parser; the relevant payload page.
  • dependency: [[trivy]] for known-CVE deps -> prove reachability from input.
Show full SKILL.md (316 more words)Show less

5. Evaluate the result

  • FINDING (crash, leak, anomaly, logic flaw): record it in findings.md with class + location. Continue looping from the finding -> go to 6. Do NOT stop at the first anomaly.
  • NOTHING after the bounded effort: append the approach + why-exhausted to deadends.md, then go to 3 and pick a different hypothesis/approach.

6. Deepen the finding (the loop continues from here)

A finding spawns its own mini-loop - each question is an iteration, and a dead-end here pivots within the finding before abandoning it:

  1. Root cause - the exact flawed code/logic.
  2. Reachability - is it triggerable from a real attacker boundary (not just an internal call)?
  3. Exploitability - is the primitive controllable (overwrite what / leak what / which state)?
  4. Impact - RCE / memory corruption / info leak / DoS / privesc / auth bypass.
  5. Variants - is the same bug pattern present elsewhere (grep the codebase)?

7. Prove + novelty-check

  • Minimal reproducible PoC / trigger in poc/.
  • Severity + CVSS; affected versions (git blame / changelog for when introduced).
  • Novelty (decides CVE vs known): search NVD, GitHub Security Advisories, the project changelog/issues, and qmd_query the wiki. Already fixed/reported -> mark known in findings.md and pivot. Genuinely new + reachable -> candidate CVE.

8. Write up (CVE-grade)

Promote the proven finding in findings.md (or a dedicated FIND file): title, affected versions, root cause, PoC, primitive/impact, CVSS, remediation, disclosure note. Then feed the reusable technique/pattern back to the wiki (wiki/techniques/ or wiki/payloads/) via the research-ingest skill - so the next project starts ahead.


Loop control (the state machine)

setup -> surface-map -> hypothesize -> investigate -> evaluate
   evaluate: finding  -> deepen -> prove -> writeup -> (variants? back to hypothesize)
   evaluate: nothing  -> deadend -> hypothesize (different approach)
   all hypotheses exhausted -> step back: re-map a different component (2),
                               try a new target-type angle, or note the target looks hardened.
  • Log every iteration to loop.md as Iter N (date): <approach> -> <result> -> <next>. Update findings.md / deadends.md before you stop. State persists across sessions - a later session resumes the loop from loop.md.
  • Stop conditions: a proven novel vuln (success), or all current hypotheses exhausted (record the frontier + suggested new angles).

Output every iteration

Iter N: <approach> -> <result> -> <next move>, plus which files you updated. Keep the human in the loop on each pivot and each finding.

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/research of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Research next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Research compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Research this skillEncod3d-Sec/TORCH329—~1.8kAutomated safety check: PassMIT
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Vulners API Python SDKvulnersCom/api376—~2.3kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
CSO Security Auditgarrytan/gstack136k—~4.5kAutomated safety check: PassMIT
Vulnerability ScannerxenitV1/Antigravity-Workflows1307 repos~1.8kAutomated safety check: NotesMIT

Similar skills

  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.

    376 GitHub stars~2.3k tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 12 days ago
    SecurityAuto-check: notes
  • CSO Security Audit

    garrytan/gstack

    Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled.

    136k GitHub stars~4.5k tokensUpdated today
    SecurityAuto-check passed
  • Vulnerability Scanner

    xenitV1/Antigravity-Workflows

    Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows.

    130 GitHub starsUsed in 7 repos~1.8k tokens
    SecurityAuto-check: notes
  • ffuf Web Fuzzer

    AgentSecOps/SecOpsAgentKit

    Runs ffuf for DAST work: directory and file discovery, GET and POST parameter fuzzing, virtual host enumeration and filtered, recursive scans.

    220 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Research

What does Research do?

Vulnerability-research loop toward a novel CVE. An agent skill from Encod3d-Sec/TORCH. Research is an agent skill from Encod3d-Sec/TORCH. Vulnerability-research loop toward a novel CVE.

When should I use Research?

Research fits situations like: analyze this binary/library; audit this code for vulns.

How do I install Research in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill research -a claude-code`. Or copy the skill folder (skills/research in Encod3d-Sec/TORCH) into .claude/skills/research in your project. Claude Code loads it when a task matches its description.

How do I install Research in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill research -a codex`. Or copy the skill folder (skills/research in Encod3d-Sec/TORCH) into .agents/skills/research in your project. Codex loads it when a task matches its description.

Can I use Research in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill research -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/research, .gemini/skills/research, .github/skills/research and .opencode/skills/research in your project.

What does Research need to run?

Going by SKILL.md and its folder, Research needs the command-line tools its instructions call (bash, python3 and git). Our summary lists: Python 3.

Does Research access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Research safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Research use?

Research is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Research use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Research?

Skills that share tags, products or a category with Research: Security Audit Scanner (ruvnet/ruflo, 74k stars), Vulners API Python SDK (vulnersCom/api, 376 stars), Forensify (alexgreensh/repo-forensics, 188 stars) and CSO Security Audit (garrytan/gstack, 136k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Research?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.