Foundatio
FoundatioFx/Foundatio
A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.
Subdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the…
$ npx skills add PentesterFlow/agent --skill takeover -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install PentesterFlow/agent takeover --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/PentesterFlow/agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/takeover .claude/skills/takeover && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "takeover" agent skill from https://github.com/PentesterFlow/agent/tree/main/skills/takeover into .claude/skills/takeover/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "takeover", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/PentesterFlow/agent/tree/main/skills/takeoverType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add PentesterFlow/agent --skill takeover -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install PentesterFlow/agent takeover --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PentesterFlow/agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/takeover .agents/skills/takeover && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "takeover" agent skill from https://github.com/PentesterFlow/agent/tree/main/skills/takeover into .agents/skills/takeover/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "takeover", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PentesterFlow/agent --skill takeover -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install PentesterFlow/agent takeover --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PentesterFlow/agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/takeover .cursor/skills/takeover && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "takeover" agent skill from https://github.com/PentesterFlow/agent/tree/main/skills/takeover into .cursor/skills/takeover/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "takeover", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/PentesterFlow/agent.git --path skills/takeover--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add PentesterFlow/agent --skill takeover -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install PentesterFlow/agent takeover --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PentesterFlow/agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/takeover .gemini/skills/takeover && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "takeover" agent skill from https://github.com/PentesterFlow/agent/tree/main/skills/takeover into .gemini/skills/takeover/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "takeover", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install PentesterFlow/agent takeoverInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add PentesterFlow/agent --skill takeover -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/PentesterFlow/agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/takeover .github/skills/takeover && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "takeover" agent skill from https://github.com/PentesterFlow/agent/tree/main/skills/takeover into .github/skills/takeover/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "takeover", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PentesterFlow/agent --skill takeover -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install PentesterFlow/agent takeover --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PentesterFlow/agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/takeover .opencode/skills/takeover && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "takeover" agent skill from https://github.com/PentesterFlow/agent/tree/main/skills/takeover into .opencode/skills/takeover/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "takeover", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
takeoverSubdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the…
Takeover is an agent skill from PentesterFlow/agent. Subdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the engine's HTTP fingerprint, then prove impact by claiming the resource in scope. Use when enumerating subdomains for dangling CNAME/NS records pointing at unclaimed third-party services.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `payloads/fingerprints.json`).
It sits in Backend & APIs, covering File uploads and storage. It works with Microsoft Azure, Netlify, GitHub and Shopify. The repository describes itself as: Agentic offensive-security in your terminal. The licence is Apache-2.0.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0759d87. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
httpshellread_payloadsfile_writeFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curljqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
wishpond.comcrt.shjldc.meapi.hackertarget.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Takeover loads about 3.3k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 1,359 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from PentesterFlow/agent at commit 0759d87, republished under its Apache-2.0 licence (© PentesterFlow). 1,359 words, ~3,300 tokens.
.claude/skills/takeover/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.A subdomain points (via CNAME, NS, or an A record on a shared host) at a
third-party service. The resource on that service was deleted, expired,
or never claimed — but the DNS record still exists. An attacker registers
the same resource on the provider and serves arbitrary content on the
victim's hostname. Severity is usually high to critical because
the takeover puts the attacker inside the victim's origin (cookie scope,
CSP allowlists, OAuth redirect_uri allowlists, SAML SP entity IDs,
email DKIM/SPF includes, ...).
Stay in scope. Only test takeovers against domains the program explicitly authorizes. A successful takeover is serving content on someone else's host — drop a benign HTML file (
takeover proof for <handle>, contact <email>) and stop.
Execution rule: operate on real subdomains and provider fingerprints from the scoped program. Never write literal placeholders such as <provider>, <handle>, or <email> to files; ask once for proof text if a provider requires a claim page.
Use whatever recon you have. Curl-first sources you can hit without extra tooling:
# CT logs via crt.sh
curl -s 'https://crt.sh/?q=%25.target.example.com&output=json' \
| jq -r '.[].name_value' | sed 's/^\*\.//' | sort -u > subs.txt
# Anubis-DB
curl -s 'https://jldc.me/anubis/subdomains/target.example.com' \
| jq -r '.[]' >> subs.txt
# Hackertarget (rate-limited)
curl -s 'https://api.hackertarget.com/hostsearch/?q=target.example.com' \
| cut -d, -f1 >> subs.txt
sort -u subs.txt -o subs.txtIf [[recon]] is loaded, prefer those flows for the enumeration step.
# Pull CNAMEs in one batch (works on macOS/Linux with dig)
while read -r sub; do
cname=$(dig +short CNAME "$sub" | head -n1)
if [ -n "$cname" ]; then printf '%s\tCNAME\t%s\n' "$sub" "$cname"; fi
done < subs.txt > resolved.tsv
# NS delegation (rare but high-severity)
while read -r sub; do
ns=$(dig +short NS "$sub")
if [ -n "$ns" ]; then printf '%s\tNS\t%s\n' "$sub" "$(echo "$ns" | tr '\n' ',')"; fi
done < subs.txt >> resolved.tsvYou're looking for:
app.target.com → app.elasticbeanstalk.com) where the resource at that provider is unclaimed.zone.target.com NS ns1.dnsmadeeasy.com where the
zone no longer exists on dnsmadeeasy).# Find CNAMEs whose target doesn't resolve at all
awk -F'\t' '$2=="CNAME" {print $3}' resolved.tsv | while read -r t; do
dig +short "$t" >/dev/null 2>&1 || echo "$t (NXDOMAIN target)"
donePull the full fingerprint database:
read_payloads(skill="takeover", file="fingerprints.json")The JSON Lines file lists, for each provider:
service — human label.cname — regex of the target hostname.status — vulnerable / edge-case / not-vulnerable.fingerprint — string to grep for in the HTTPS response body.http_status — typical status code (404, 200, etc.).notes — claim-flow gotchas.For each CNAME match, fetch the response and grep:
# Example: subdomain points at GitHub Pages
curl -sk -H "Host: lost.target.com" https://lost.target.com/ \
| grep -F "There isn't a GitHub Pages site here."A hit on status: vulnerable plus the fingerprint in the response body is
the takeover signal. Don't trust the fingerprint alone — many providers
serve the same string on a legitimately-not-yet-deployed site that's still
claimed by the owner. Confirm-step (4) is mandatory.
The trap: the resource may be unclaimed by anyone visible to you, but the legitimate owner may still hold it via an account you can't see (e.g. the Heroku app exists in their account but is paused). False-positive report rates on subdomain takeover are notorious.
Confirmation paths, in order of preference:
Out-of-band canary. Attempt to register the resource (e.g. create
a Heroku app named lost-target). If the provider says "name taken"
without serving you the fingerprint, it's a false positive — someone
has it.
Successful claim + benign content. When the registration succeeds, serve a static HTML file proving ownership:
<!doctype html>
<title>Subdomain Takeover PoC</title>
<h1>Subdomain Takeover</h1>
<p>This subdomain (<code>lost.target.com</code>) was claimable on
<em><provider></em> by anyone. Reported by <handle>
to <program>. Contact: <email>.</p>Fetch the subdomain again over HTTPS — your content must come back.
Screenshot + curl response in the report.
Do NOT:
If a subdomain delegates DNS to a third-party provider via NS records and the zone is unclaimed on that provider, you control all records under the subdomain — far more dangerous than a single CNAME takeover. Common providers seen here: DNSMadeEasy, Bizland, EasyDNS, Yahoo Small Business, NS1, Hurricane Electric, MyDomain, Domain.com.
Detection: dig NS sub.target.com returns a provider's nameservers, but
querying those nameservers for the zone returns REFUSED or SERVFAIL.
for ns in $(dig +short NS sub.target.com); do
echo "=== $ns ==="
dig @"$ns" sub.target.com SOA
doneA REFUSED/SERVFAIL from all of the listed nameservers, combined
with the provider being one that lets you create zones with arbitrary
names, is the takeover primitive.
| Service | CNAME pattern | Fingerprint substring | Status |
|---|---|---|---|
| GitHub Pages | *.github.io | There isn't a GitHub Pages site here. | vulnerable |
| Heroku | *.herokuapp.com, *.herokudns.com | No such app / There's nothing here, yet. | vulnerable |
| AWS S3 (website) | *.s3-website-*.amazonaws.com, *.s3.amazonaws.com | NoSuchBucket | vulnerable |
| Azure App Service | *.azurewebsites.net | 404 Web Site not found. | vulnerable |
| Azure Cloud Service | *.cloudapp.net, *.cloudapp.azure.com | 404 Web Site not found. | vulnerable |
| Azure Traffic Manager | *.trafficmanager.net | NXDOMAIN on profile | vulnerable |
| Azure Storage | *.blob.core.windows.net | NXDOMAIN | vulnerable |
| Azure CDN | *.azureedge.net | NXDOMAIN / Bad Request | edge-case |
| Netlify | *.netlify.app, *.netlify.com | Not Found - Request ID | vulnerable |
| Heroku SSL endpoint | *.herokussl.com | varies | edge-case |
| Vercel / Now | *.vercel.app, cname.vercel-dns.com | 404: NOT_FOUND / The deployment could not be found | edge-case |
| Shopify | *.myshopify.com | Sorry, this shop is currently unavailable. | vulnerable |
| Tumblr | *.tumblr.com (custom domain) | Whatever you were looking for doesn't currently exist at this address. | vulnerable |
| Surge.sh | *.surge.sh | project not found | vulnerable |
| Ghost | *.ghost.io | The thing you were looking for is no longer here, or never was | vulnerable |
| Pantheon | *.pantheonsite.io | The gods are wise, but do not know of the site which you seek. | vulnerable |
| Squarespace | various | No Such Account / Squarespace - No Such Account | edge-case |
| Tilda | *.tilda.ws | Please renew your subscription | vulnerable |
| Unbounce | *.unbouncepages.com | The requested URL was not found on this server. | vulnerable |
| UserVoice | *.uservoice.com | This UserVoice subdomain is currently available! | vulnerable |
| Strikingly | *.s.strikinglydns.com | PAGE NOT FOUND. | vulnerable |
| Helpjuice | *.helpjuice.com | We could not find what you're looking for. | vulnerable |
| HelpScout | *.helpscoutdocs.com | No settings were found for this company: | vulnerable |
| Bitbucket | *.bitbucket.io | Repository not found | vulnerable |
| Cargo Collective | *.cargocollective.com | If you're moving your domain away from Cargo | vulnerable |
| Statuspage | *.statuspage.io | You are being redirected. (302 to statuspage 404) | edge-case |
| Acquia | *.acquia-sites.com | The site you are looking for could not be found. | vulnerable |
| Aha | *.aha.io | There is no portal here ... sending you back to Aha! | vulnerable |
| Anima | *.animaapp.io | If this is your website and you've just created it | vulnerable |
| Brightcove | various | <p class="bc-gallery-error-code">Error Code: 404</p> | vulnerable |
| Campaign Monitor | createsend.com | Trying to access your account? | vulnerable |
| Canny | *.canny.io | Company Not Found | vulnerable |
| Fastly | *.fastly.net | Fastly error: unknown domain | edge-case |
| Frontify | *.frontify.com | Brand not found | vulnerable |
| Gemfury | *.fury.site | 404: This page could not be found. | vulnerable |
| GetResponse | varies | With GetResponse Landing Pages, lead generation has never been easier | vulnerable |
| Hatena Blog | hatenablog.com | Japanese error string | vulnerable |
| HelpRescue | *.helprace.com | Help Center Closed | edge-case |
| JetBrains | *.youtrack.cloud | is not a registered InCloud YouTrack | vulnerable |
| Kinsta | *.kinsta.cloud | No Site For Domain | edge-case |
| LaunchRock | *.launchrock.com | It looks like you may have taken a wrong turn somewhere. | vulnerable |
| Mashery | *.mashery.com | Unrecognized domain | edge-case |
| Pingdom | *.stats.pingdom.com | pingdom page | edge-case |
| Proposify | *.proposify.com | If you need immediate assistance | vulnerable |
| Readme | *.readme.io | Project doesnt exist... yet! | vulnerable |
| SendGrid | varies | parked landing | edge-case |
| ShortIO | *.shortio.app | 404, please check the URL. | vulnerable |
| Smartling | *.smartling.com | Domain is not configured | vulnerable |
| Thinkific | *.thinkific.com | You may have mistyped the address or the page may have moved. | vulnerable |
| Uberflip | *.uberflip.com | The page you are looking for is not found | vulnerable |
| Vend | *.vendecommerce.com | Looks like you've traveled too far into cyberspace. | vulnerable |
| Webflow | proxy-ssl.webflow.com | The page you are looking for doesn't exist or has been moved. | vulnerable |
| Wishpond | varies | https://www.wishpond.com/404?campaign= | vulnerable |
| Wordpress | *.wordpress.com | Do you want to register | edge-case |
| WP Engine | *.wpengine.com | The site you were looking for couldn't be found. | edge-case |
| Worksites | varies | Hello! Sorry, but the website you’re looking for doesn’t exist. | vulnerable |
| Cloudfront | *.cloudfront.net | The request could not be satisfied | edge-case |
| Google Cloud Storage | *.storage.googleapis.com | NoSuchBucket | vulnerable |
The full database — including HTTP status codes, claim notes, and edge-case
explanations for every entry — is in payloads/fingerprints.json (see the
read_payloads invocation in section 3).
If you have these installed, they automate sections 1–3:
subjack — Go scanner with built-in fingerprints. subjack -w subs.txt -t 100 -timeout 30 -ssl -c fingerprints.json -vsubzy — newer alternative.nuclei — nuclei -l subs.txt -tags takeover runs the community templates.tko-subs — also script-based.aquatone — screenshots + detection in one pass.You do not need any of these to do the work; sections 2–4 are
do-able with dig + curl + the JSON fingerprint file.
For each confirmed takeover:
lost.target.com).lost.target.com CNAME bucket.s3.amazonaws.com → unclaimed).redirect_uri lists, SAML entity IDs, mail SPF/DKIM, or session
domains include the parent — that's where the severity comes from.Release the claimed resource after the program triages.
© PentesterFlow, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/takeover of PentesterFlow/agent.
Open the folder on GitHubat commit 0759d87
Takeover next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Takeover this skillPentesterFlow/agent | 1.4k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| FoundatioFoundatioFx/Foundatio | 2.1k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| Kql ValidatorAzure/azqr | 794 | — | ~703 | Automated safety check: Pass | MIT | |
| Maplibre Pmtiles Patternsmaplibre/maplibre-agent-skills | 151 | — | ~4.6k | Automated safety check: Pass | Custom licence | |
| Authmicrosoft/apm | 4k | — | ~756 | Automated safety check: Pass | MIT | |
| Azure Storage Blob Pymicrosoft/skills | 3.1k | — | ~2.3k | Automated safety check: Pass | MIT |
FoundatioFx/Foundatio
A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.
Azure/azqr
Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions.
maplibre/maplibre-agent-skills
Serverless vector and raster tiles with PMTiles for MapLibre GL JS — single-file format, HTTP range requests, hosting on S3/R2/GitHub Pages, generating with Planetiler or tippecanoe, and the pmtiles…
microsoft/apm
Activate when code touches token management, credential resolution, git auth flows, GITHUBAPMPAT, ADOAPMPAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth'…
microsoft/skills
Azure Blob Storage SDK for Python. An agent skill from microsoft/skills.
microsoft/skills
Azure Blob Storage library for Rust. An agent skill from microsoft/skills.
PentesterFlow/agent
Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization.
PentesterFlow/agent
Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology.
PentesterFlow/agent
Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or…
PentesterFlow/agent
Web vulnerability hunting playbook. An agent skill from PentesterFlow/agent.
Works with
Categories
Subdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the…. Takeover is an agent skill from PentesterFlow/agent.), confirm with the engine's HTTP fingerprint, then prove impact by claiming the resource in scope.
Takeover fits situations like: enumerating subdomains for dangling CNAME/NS records pointing at unclaimed third-party services; tasks that involve File uploads and storage.
Run `npx skills add PentesterFlow/agent --skill takeover -a claude-code`. Or copy the skill folder (skills/takeover in PentesterFlow/agent) into .claude/skills/takeover in your project. Claude Code loads it when a task matches its description.
Run `npx skills add PentesterFlow/agent --skill takeover -a codex`. Or copy the skill folder (skills/takeover in PentesterFlow/agent) into .agents/skills/takeover in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PentesterFlow/agent --skill takeover -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/takeover, .gemini/skills/takeover, .github/skills/takeover and .opencode/skills/takeover in your project.
Going by SKILL.md and its folder, Takeover needs the command-line tools its instructions call (curl and jq). Its frontmatter pre-approves these tools: http, shell, read_payloads, file_write.
SKILL.md names 4 domains. In commands or code: wishpond.com, crt.sh, jldc.me and api.hackertarget.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Takeover is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Takeover: Foundatio (FoundatioFx/Foundatio, 2.1k stars), Kql Validator (Azure/azqr, 794 stars), Maplibre Pmtiles Patterns (maplibre/maplibre-agent-skills, 151 stars) and Auth (microsoft/apm, 4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
PentesterFlow (a GitHub user) maintains it in PentesterFlow/agent, which has 1,389 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on August 31, 2026.
Source: PentesterFlow/agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.