Security Audit Scanner
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
Vulnerability-research loop toward a novel CVE. An agent skill from Encod3d-Sec/TORCH.
$ npx skills add Encod3d-Sec/TORCH --skill research -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Encod3d-Sec/TORCH research --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/research .claude/skills/research && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "research" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/research into .claude/skills/research/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "research", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Encod3d-Sec/TORCH/tree/main/skills/researchType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Encod3d-Sec/TORCH --skill research -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Encod3d-Sec/TORCH research --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/research .agents/skills/research && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "research" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/research into .agents/skills/research/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "research", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Encod3d-Sec/TORCH --skill research -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Encod3d-Sec/TORCH research --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/research .cursor/skills/research && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "research" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/research into .cursor/skills/research/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "research", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Encod3d-Sec/TORCH.git --path skills/research--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Encod3d-Sec/TORCH --skill research -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Encod3d-Sec/TORCH research --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/research .gemini/skills/research && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "research" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/research into .gemini/skills/research/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "research", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Encod3d-Sec/TORCH researchInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Encod3d-Sec/TORCH --skill research -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/research .github/skills/research && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "research" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/research into .github/skills/research/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "research", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Encod3d-Sec/TORCH --skill research -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Encod3d-Sec/TORCH research --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/research .opencode/skills/research && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "research" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/research into .opencode/skills/research/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "research", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
researchVulnerability-research loop toward a novel CVE. An agent skill from Encod3d-Sec/TORCH.
Research is an agent skill from Encod3d-Sec/TORCH. Vulnerability-research loop toward a novel CVE. Target triage - attack-surface map - ranked hypotheses - investigate (RE / fuzz / audit) - a finding deepens the loop, a dead-end pivots to a new approach. Uses the full wiki + hunt skillset. Scaffolds and persists state under raw/research/<project/. Triggers - "research", "find a cve", "analyze this binary/library", "audit this code for vulns".
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Vulnerability scanning, Threat modeling and Creative writing and fiction. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bashpython3gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Research loads about 1.8k tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 788 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 788 words, ~1,846 tokens.
.claude/skills/research/SKILL.md (or your agent's skills folder).Find and prove one novel vulnerability in a target (binary, library, web app/API, firmware, protocol, or source repo). The loop is persistent, resumable, and anti-loop: findings deepen it, dead-ends pivot it, and every step is driven by the knowledge base.
This skill is the research analog of the engagement framework: raw/research/<project>/ is to research what targets/<eng>/ is to an engagement.
wsl -d kali-linux -u kali -- git clone <url> /home/kali/<name>), releases by download.bash setup/new-research.sh <project_name> -> raw/research/<project>/{target,surface,findings,deadends,loop}.md + poc/ (also sets it active in raw/research/active.md, so SessionStart surfaces its status).target.md: what it is, version, language, build/run commands, trust boundaries.Read raw/research/<project>/{loop.md, deadends.md, findings.md} before acting. Never re-run a logged dead-end without new input. Resume from the last iteration. This is the anti-loop rule - the same discipline engagements use. Run python3 scripts/research_status.py for the current phase + ranked next move (also auto-surfaced at SessionStart from raw/research/active.md).
surface.md)qmd_query the target's tech/language/framework first, then map by type:
| Target type | First moves | Knowledge base |
|---|---|---|
| binary / executable | checksec, strings, RE entry + parsers, identify input handling | [[reverse-engineering]] [[ghidra]] [[radare2]] [[binary-exploitation]] [[memory-safety-bugs]] [[fuzzing]] [[aflplusplus]] [[gdb-gef]] |
| C/C++ library | grep dangerous APIs, build a fuzz harness, map public API | [[memory-safety-bugs]] [[fuzzing]] [[libfuzzer]] [[aflplusplus]] [[static-code-analysis]] [[semgrep]] [[codeql]] |
| web app / API | map routes, auth, sinks; diff vs known framework CVEs | web hunt skills (sqli/idor/auth/injection/deser/ssrf/upload) + [[source-audit-checklist]] [[static-code-analysis]] |
| firmware | binwalk -Me, extract rootfs, then treat components as binary/web | [[firmware-hardware]] [[binwalk]] |
| protocol / network service | RE the parser/state machine, fuzz the wire format | [[protocol-attacks]] [[fuzzing]] [[aflplusplus]] [[reverse-engineering]] [[ghidra]] |
| source repo (any lang) | audit + dependency CVE review + secret/history scan | [[source-audit-checklist]] [[static-code-analysis]] [[semgrep]] [[codeql]] [[trivy]] [[secret-hunting]] [[git-exposure]] + the matching vuln-class page |
Record in surface.md: entry points (attacker-controlled input), parsers/deserializers, dangerous sinks, privileged ops, dependencies with CVE history.
loop.md)From the surface + knowledge base, write hypotheses as <input/location> + <bug class> = <expected primitive>. Rank by: reachable from an attacker boundary, attacker-controlled, lands in a dangerous sink, historically buggy area, weak/old dependency. Pick the highest-value untested hypothesis (skip anything in deadends.md).
Apply the matching technique + hunt skill + tool to the chosen hypothesis. Bound the effort up front (e.g. fuzz N hours / M execs; audit this component once; sweep this payload class once).
hunt-* skill (auth/idor/injection/deser/ssrf/upload/bizlogic/smuggling) to confirm with the payload arsenal.findings.md with class + location. Continue looping from the finding -> go to 6. Do NOT stop at the first anomaly.deadends.md, then go to 3 and pick a different hypothesis/approach.A finding spawns its own mini-loop - each question is an iteration, and a dead-end here pivots within the finding before abandoning it:
poc/.git blame / changelog for when introduced).qmd_query the wiki. Already fixed/reported -> mark known in findings.md and pivot. Genuinely new + reachable -> candidate CVE.Promote the proven finding in findings.md (or a dedicated FIND file): title, affected versions, root cause, PoC, primitive/impact, CVSS, remediation, disclosure note. Then feed the reusable technique/pattern back to the wiki (wiki/techniques/ or wiki/payloads/) via the research-ingest skill - so the next project starts ahead.
setup -> surface-map -> hypothesize -> investigate -> evaluate
evaluate: finding -> deepen -> prove -> writeup -> (variants? back to hypothesize)
evaluate: nothing -> deadend -> hypothesize (different approach)
all hypotheses exhausted -> step back: re-map a different component (2),
try a new target-type angle, or note the target looks hardened.loop.md as Iter N (date): <approach> -> <result> -> <next>. Update findings.md / deadends.md before you stop. State persists across sessions - a later session resumes the loop from loop.md.Iter N: <approach> -> <result> -> <next move>, plus which files you updated. Keep the human in the loop on each pivot and each finding.
© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/research of Encod3d-Sec/TORCH.
Open the folder on GitHubat commit d21b6c9
Research next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Research this skillEncod3d-Sec/TORCH | 329 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Security Audit Scannerruvnet/ruflo | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | |
| Vulners API Python SDKvulnersCom/api | 376 | — | ~2.3k | Automated safety check: Pass | MIT | |
| Forensifyalexgreensh/repo-forensics | 188 | — | ~2.5k | Automated safety check: Notes | Custom licence | |
| CSO Security Auditgarrytan/gstack | 136k | — | ~4.5k | Automated safety check: Pass | MIT | |
| Vulnerability ScannerxenitV1/Antigravity-Workflows | 130 | 7 repos | ~1.8k | Automated safety check: Notes | MIT |
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
vulnersCom/api
A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
garrytan/gstack
Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled.
xenitV1/Antigravity-Workflows
Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows.
AgentSecOps/SecOpsAgentKit
Runs ffuf for DAST work: directory and file discovery, GET and POST parameter fuzzing, virtual host enumeration and filtered, recursive scans.
Encod3d-Sec/TORCH
Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.
Encod3d-Sec/TORCH
Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.
Encod3d-Sec/TORCH
Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.
Encod3d-Sec/TORCH
Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.
Encod3d-Sec/TORCH
Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.
Encod3d-Sec/TORCH
Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.
Categories
Vulnerability-research loop toward a novel CVE. An agent skill from Encod3d-Sec/TORCH. Research is an agent skill from Encod3d-Sec/TORCH. Vulnerability-research loop toward a novel CVE.
Research fits situations like: analyze this binary/library; audit this code for vulns.
Run `npx skills add Encod3d-Sec/TORCH --skill research -a claude-code`. Or copy the skill folder (skills/research in Encod3d-Sec/TORCH) into .claude/skills/research in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Encod3d-Sec/TORCH --skill research -a codex`. Or copy the skill folder (skills/research in Encod3d-Sec/TORCH) into .agents/skills/research in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill research -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/research, .gemini/skills/research, .github/skills/research and .opencode/skills/research in your project.
Going by SKILL.md and its folder, Research needs the command-line tools its instructions call (bash, python3 and git). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Research is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Research: Security Audit Scanner (ruvnet/ruflo, 74k stars), Vulners API Python SDK (vulnersCom/api, 376 stars), Forensify (alexgreensh/repo-forensics, 188 stars) and CSO Security Audit (garrytan/gstack, 136k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.
Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.