Agent skill

Research Ingest

by Encod3d-Sec in Encod3d-Sec/TORCH

Ingest a CVE writeup, blog post, advisory, or GitHub repo into the wiki - fetch, dedup via sources:, update the right technique/tool page(s), re-index.

MITAuto-check passedSecurity

Install Research Ingest

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill research-ingest -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH research-ingest --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/workflow/research-ingest .claude/skills/research-ingest && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
research-ingest
GitHub stars
329
Token cost
~572 tokens
SKILL.md length
270 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Ingest a CVE writeup, blog post, advisory, or GitHub repo into the wiki - fetch, dedup via sources:, update the right technique/tool page(s), re-index.

  • Works in 7 steps: Fetch the source. → Find the home page. qmd_query "" via… → Dedup (skip rule). Read only the target… → …
  • Tasks that involve Vulnerability scanning
  • SKILL.md covers Procedure and Guardrails
  • Calls python3 and npm

What it does

Research Ingest is an agent skill from Encod3d-Sec/TORCH. Ingest a CVE writeup, blog post, advisory, or GitHub repo into the wiki - fetch, dedup via sources:, update the right technique/tool page(s), re-index. Generic knowledge only; never client data.

Its SKILL.md is about 570 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning and Blog and article writing. It works with GitHub. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Tasks that involve Vulnerability scanning
  • Tasks that involve Blog and article writing

Example prompts

  • “/research-ingest”

Requirements

  • Python 3
  • Node.js

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Fetch the source.
  2. Find the home page. qmd_query "" via wiki-search MCP -> identify the technique/tool page that should hold this. One class = one page.
  3. Dedup (skip rule). Read only the target page's frontmatter. If the ingest slug is already in sources:, STOP - already ingested. Otherwise…
  4. Synthesise the new payload / bypass / CVE chain / detail into the page's existing sections (Methodology, Key payloads, Bypasses and…
  5. Tool page if a new standalone tool appears: create/update wiki/tools/.md.
  6. Record the source. Add the slug to the page's sources: list; bump date_updated. Register URL/path + slug in raw/manifest.md.
  7. Re-index + log. python3 scripts/gen_index.py (catalog) and, after a bulk session, qmd update (search index). Append a one-line entry to…

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Research Ingest loads about 572 tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 270 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~572

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 270 words, ~572 tokens.

Download SKILL.mdSave it as .claude/skills/research-ingest/SKILL.md (or your agent's skills folder).
name
research-ingest
description
Ingest a CVE writeup, blog post, advisory, or GitHub repo into the wiki - fetch, dedup via sources:, update the right technique/tool page(s), re-index. Generic knowledge only; never client data.

Research Ingest

Turn an external source (URL or raw/research/ file) into durable wiki knowledge. Synthesise into existing technique/tool pages; do NOT create one page per source. Full workflow: docs/workflows.md (Research ingest / Git repo ingest).

Procedure

  1. Fetch the source.

    • URL: defuddle parse <url> --md for clean markdown (install: npm i -g defuddle); fall back to the WebFetch tool.
    • Local: read the file under raw/research/. GitHub repo: clone via WSL only (wsl -d kali-linux -u kali -- git clone <url> /home/kali/<name>), then read source/README.
  2. Find the home page. qmd_query "<technique/CVE class>" via wiki-search MCP -> identify the technique/tool page that should hold this. One class = one page.

  3. Dedup (skip rule). Read only the target page's frontmatter. If the ingest slug is already in sources:, STOP - already ingested. Otherwise continue.

  4. Synthesise the new payload / bypass / CVE chain / detail into the page's existing sections (Methodology, Key payloads, Bypasses and variants). Add concrete commands in code blocks. Reconstruct any image into a code block - never embed images. No em-dashes.

  5. Tool page if a new standalone tool appears: create/update wiki/tools/<tool>.md.

  6. Record the source. Add the slug to the page's sources: list; bump date_updated. Register URL/path + slug in raw/manifest.md.

  7. Re-index + log. python3 scripts/gen_index.py (catalog) and, after a bulk session, qmd update (search index). Append a one-line entry to session/log.md. Run python3 scripts/lint-wiki.py -q - must be clean.

Guardrails

  • Generic only. Wiki holds reusable methodology; client/engagement specifics stay in targets/<eng>/. Reusable default creds -> wiki/cheatsheets/default-credentials.md; reusable request patterns -> api-request-findings.md.
  • Prefer enriching an existing page over creating a new one. New page only for a genuinely new technique/tool class.

Report: page(s) updated + slug added + lint status.

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/workflow/research-ingest of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Research Ingest next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Research Ingest compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Research Ingest this skillEncod3d-Sec/TORCH329—~572Automated safety check: PassMIT
Security AdvisoryMidnightBSD/src114—~2.2kAutomated safety check: PassCustom licence
Security Vulnerability Analysiseclipse-ankaios/ankaios125—~1.5kAutomated safety check: PassApache-2.0
Warp Vulnerability Triagewarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0
Cve Doctorgetlago/lago-front163—~2.9kAutomated safety check: PassMIT
Deal With Security Advisorypaperclipai/paperclip99k—~2kAutomated safety check: PassMIT

Similar skills

  • Security Advisory

    MidnightBSD/src

    Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING…

    114 GitHub stars~2.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Vulnerability Analysis

    eclipse-ankaios/ankaios

    Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.

    125 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed
  • Cve Doctor

    getlago/lago-front

    Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix.

    163 GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed
  • Deal With Security Advisory

    paperclipai/paperclip

    Handle confidential GitHub Security Advisory response for Paperclip.

    99k GitHub stars~2k tokensUpdated today
    SecurityAuto-check passed
  • Snapshot

    boostsecurityio/poutine

    Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

    523 GitHub stars~214 tokensUpdated yesterday
    SecurityAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Research Ingest

What does Research Ingest do?

Ingest a CVE writeup, blog post, advisory, or GitHub repo into the wiki - fetch, dedup via sources:, update the right technique/tool page(s), re-index. Research Ingest is an agent skill from Encod3d-Sec/TORCH. Ingest a CVE writeup, blog post, advisory, or GitHub repo into the wiki - fetch, dedup via sources:, update the right technique/tool page(s), re-index.

When should I use Research Ingest?

Research Ingest fits situations like: tasks that involve Vulnerability scanning; tasks that involve Blog and article writing.

How do I install Research Ingest in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill research-ingest -a claude-code`. Or copy the skill folder (skills/workflow/research-ingest in Encod3d-Sec/TORCH) into .claude/skills/research-ingest in your project. Claude Code loads it when a task matches its description.

How do I install Research Ingest in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill research-ingest -a codex`. Or copy the skill folder (skills/workflow/research-ingest in Encod3d-Sec/TORCH) into .agents/skills/research-ingest in your project. Codex loads it when a task matches its description.

Can I use Research Ingest in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill research-ingest -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/research-ingest, .gemini/skills/research-ingest, .github/skills/research-ingest and .opencode/skills/research-ingest in your project.

What does Research Ingest need to run?

Going by SKILL.md and its folder, Research Ingest needs the command-line tools its instructions call (python3 and npm). Our summary lists: Python 3; Node.js.

Does Research Ingest access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Research Ingest safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Research Ingest use?

Research Ingest is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Research Ingest use?

About 572 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Research Ingest?

Skills that share tags, products or a category with Research Ingest: Security Advisory (MidnightBSD/src, 114 stars), Security Vulnerability Analysis (eclipse-ankaios/ankaios, 125 stars), Warp Vulnerability Triage (warpdotdev/warp, 65k stars) and Cve Doctor (getlago/lago-front, 163 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Research Ingest?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.