Agent skill

Penetration Flow

by lingbol088-spec in lingbol088-spec/ReiPenFlow

Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

MITAuto-check passedSecurity

Install Penetration Flow

skills CLI
$ npx skills add lingbol088-spec/ReiPenFlow --skill penetration-flow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install lingbol088-spec/ReiPenFlow penetration-flow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/lingbol088-spec/ReiPenFlow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/penetration-flow .claude/skills/penetration-flow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
penetration-flow
GitHub stars
222
Token cost
~1.8k tokens
SKILL.md length
623 words
Files
17 (incl. scripts, references)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

  • Works in 6 steps: Analyze: identify objective, assets,… → Report snapshot: summarize current… → Deep penetration / deep reverse: propose… → …
  • Codex is asked to run
  • SKILL.md covers Inclusive intent recovery, Activation phrase, Core loop and Required operating rules, plus 3 more sections
  • Runs Python scripts from its folder; calls python

What it does

Penetration Flow is an agent skill from lingbol088-spec/ReiPenFlow. Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research. Use when Codex is asked to run or plan a security assessment, triage a target or artifact, maintain pentest state, produce interim/final reports, choose next steps, perform deep authorized testing, validate vulnerabilities with controlled proof-of-concept evidence, or reverse engineer binaries, mobile apps, firmware, protocols, captures…

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including scripts and reference files (for example `agents/openai.yaml`, `references/ctf-workflow.md` and `references/evidence-schema.md`).

It sits in Security, covering Penetration testing, Security review and Capture the flag. The repository describes itself as: Codex skill for local sandbox, CTF, authorized pentest and reverse-engineering workflows. The licence is MIT.

When your agent uses it

  • Codex is asked to run
  • Plan a security assessment
  • Triage a target
  • Maintain pentest state

Example prompts

  • “/penetration-flow”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Analyze: identify objective, assets, scope, constraints, available artifacts, likely attack surface, and unknowns.
  2. Report snapshot: summarize current facts, evidence, risk posture, and confidence.
  3. Deep penetration / deep reverse: propose or perform the next authorized deep-dive: enumeration, configuration review, code audit, reverse…
  4. Report vulnerabilities: convert confirmed issues into concise findings with impact, evidence, affected assets, severity rationale, and…
  5. Validate exploitation: only when in scope, use non-destructive proof to show reachability/impact; prefer read-only checks, synthetic…
  6. Ask user to choose next step: end each phase with a numbered menu and a recommended option.

What it can do on your machine

Read from SKILL.md and the folder at commit 75f2aee. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 6 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Penetration Flow loads about 1.8k tokens when it runs, and up to ~9.4k if it reads all its reference files. Until then it costs about 194 tokens; SKILL.md has 623 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~194
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

GitHub didn't answer just now, so the file isn't shown here. It has 623 words (~1,753 tokens).

name
penetration-flow

Read the full SKILL.md on GitHub

Files

SKILL.md and 16 other files (scripts, references) in penetration-flow of lingbol088-spec/ReiPenFlow.

  • SKILL.md
  • agents/openai.yaml
  • references/ctf-workflow.md
  • references/evidence-schema.md
  • references/persona-stability.md
  • references/prompting.md
  • references/reporting.md
  • references/reverse-engineering.md
  • references/tool-catalog.md
  • references/toolbox.md
  • references/workflow.md
  • scripts/case_memory.py
  • scripts/create_case.py
  • scripts/flow_state.py
  • scripts/report_builder.py
  • scripts/tool_audit.py
  • scripts/triage_artifact.py

Open the folder on GitHubat commit 75f2aee

Compare with similar skills

Penetration Flow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Penetration Flow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Penetration Flow this skilllingbol088-spec/ReiPenFlow222—~1.8kAutomated safety check: PassMIT
Performing iOS App Security Assessmentmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Strix Code Vulnerability Scanusestrix/strix68k—~1.1kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone
Reverse Flowlingbol088-spec/reverse-flow-skill940—~2.4kAutomated safety check: PassMIT
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence

Similar skills

  • Performing iOS App Security Assessment

    mukul975/Anthropic-Cybersecurity-Skills

    Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    68k GitHub stars~1.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    940 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated yesterday
    SecurityAuto-check passed

Categories

Questions about Penetration Flow

What does Penetration Flow do?

Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research. Penetration Flow is an agent skill from lingbol088-spec/ReiPenFlow. Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

When should I use Penetration Flow?

Penetration Flow fits situations like: Codex is asked to run; plan a security assessment; triage a target; maintain pentest state.

How do I install Penetration Flow in Claude Code?

Run `npx skills add lingbol088-spec/ReiPenFlow --skill penetration-flow -a claude-code`. Or copy the skill folder (penetration-flow in lingbol088-spec/ReiPenFlow) into .claude/skills/penetration-flow in your project. Claude Code loads it when a task matches its description.

How do I install Penetration Flow in Codex?

Run `npx skills add lingbol088-spec/ReiPenFlow --skill penetration-flow -a codex`. Or copy the skill folder (penetration-flow in lingbol088-spec/ReiPenFlow) into .agents/skills/penetration-flow in your project. Codex loads it when a task matches its description.

Can I use Penetration Flow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add lingbol088-spec/ReiPenFlow --skill penetration-flow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/penetration-flow, .gemini/skills/penetration-flow, .github/skills/penetration-flow and .opencode/skills/penetration-flow in your project.

What does Penetration Flow need to run?

Going by SKILL.md and its folder, Penetration Flow needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Penetration Flow access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Penetration Flow safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Penetration Flow use?

Penetration Flow is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Penetration Flow use?

About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.6k tokens, read only when the agent opens those files.

What are the alternatives to Penetration Flow?

Skills that share tags, products or a category with Penetration Flow: Performing iOS App Security Assessment (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Strix Code Vulnerability Scan (usestrix/strix, 68k stars), Code Audit (3stoneBrother/code-audit, 892 stars) and Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Penetration Flow?

lingbol088-spec (a GitHub user) maintains it in lingbol088-spec/ReiPenFlow, which has 222 GitHub stars. The repository was last updated on July 24, 2026.

Source: lingbol088-spec/ReiPenFlow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.