Penetration Flow is an agent skill from lingbol088-spec/ReiPenFlow. Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research. Use when Codex is asked to run or plan a security assessment, triage a target or artifact, maintain pentest state, produce interim/final reports, choose next steps, perform deep authorized testing, validate vulnerabilities with controlled proof-of-concept evidence, or reverse engineer binaries, mobile apps, firmware, protocols, captures…
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including scripts and reference files (for example `agents/openai.yaml`, `references/ctf-workflow.md` and `references/evidence-schema.md`).
It sits in Security, covering Penetration testing, Security review and Capture the flag. The repository describes itself as: Codex skill for local sandbox, CTF, authorized pentest and reverse-engineering workflows. The licence is MIT.