Agent skill

Bloodhound Analysis

by SpecterOps in SpecterOps/skills

Use as the default router for generic BloodHound asks: check the BloodHound connection, verify MCP health, analyze BloodHound data, find or explain a path, inspect shortest paths, find a path to…

MITAuto-check passedData & Analytics

Install Bloodhound Analysis

skills CLI
$ npx skills add SpecterOps/skills --skill bloodhound-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SpecterOps/skills bloodhound-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SpecterOps/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/bloodhound/skills/bloodhound-analysis .claude/skills/bloodhound-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bloodhound-analysis
GitHub stars
704
Token cost
~1.4k tokens
SKILL.md length
536 words
Files
5 (incl. references, assets)
Skills in repo
38
Repo updated
First seen
Licence
MIT

At a glance

Use as the default router for generic BloodHound asks: check the BloodHound connection, verify MCP health, analyze BloodHound data, find or explain a path, inspect shortest paths, find a path to…

  • Works in 5 steps: Check data quality first → Find the right graph objects → Use the right composite tool before… → …
  • Unrelated network recon
  • SKILL.md covers When to use, Direct triggers, Route to instead and Required context, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Bloodhound Analysis is an agent skill from SpecterOps/skills. Use as the default router for generic BloodHound asks: check the BloodHound connection, verify MCP health, analyze BloodHound data, find or explain a path, inspect shortest paths, find a path to Domain Admin or Tier Zero, show exposure, run a BloodHound query, or triage graph results when the domain is not yet clear. Use BloodHound MCP for authorized BloodHound CE graph analysis, path triage, object lookup, data-quality checks, AD/ADCS/Azure/OpenGraph exposure mapping, and report-ready remediation output. Do not…

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files and assets (for example `agents/openai.yaml` and `references/bloodhound-mcp-tools.md`).

It sits in Data & Analytics, covering Data cleaning, Database schema design and MCP servers. It works with Model Context Protocol and Microsoft Azure. The repository describes itself as: A marketplace for LLM skills. The licence is MIT.

When your agent uses it

  • Unrelated network recon
  • For domain-specific work that is clearly AzureHound
  • OpenGraph schema design
  • Explicit Cypher authoring/review

Example prompts

  • “/bloodhound-analysis”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Check data quality first
  2. Find the right graph objects
  3. Use the right composite tool before custom Cypher
  4. Load references before writing attack queries
  5. Produce assessment-ready output

What it can do on your machine

Read from SKILL.md and the folder at commit e655f93. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bloodhound Analysis loads about 1.4k tokens when it runs, and up to ~1.8k if it reads all its reference files. Until then it costs about 175 tokens; SKILL.md has 536 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~175
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SpecterOps/skills at commit e655f93, republished under its MIT licence (© SpecterOps). 536 words, ~1,368 tokens.

Download SKILL.mdSave it as .claude/skills/bloodhound-analysis/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
bloodhound-analysis
description
Use as the default router for generic BloodHound asks: check the BloodHound connection, verify MCP health, analyze BloodHound data, find or explain a path, inspect shortest paths, find a path to Domain Admin or Tier Zero, show exposure, run a BloodHound query, or triage graph results when the domain is not yet clear. Use BloodHound MCP for authorized BloodHound CE graph analysis, path triage, object lookup, data-quality checks, AD/ADCS/Azure/OpenGraph exposure mapping, and report-ready remediation output. Do not use for unrelated network recon or for domain-specific work that is clearly AzureHound, OpenHound, OpenGraph schema design, or explicit Cypher authoring/review.
license
MIT
metadata.author
turbo
metadata.version
0.1.0
metadata.category
security

BloodHound Analysis

When to use

Use this skill as the MCP-aware router for authorized BloodHound analysis. It is optimized for repeatable graph workflows: dataset checks, object lookup, path analysis, query design, ADCS/Azure/OpenGraph code-review, and report-ready output.

Direct triggers

Use this skill when the task mentions any of the following:

  • check the BloodHound connection
  • verify BloodHound MCP
  • is BloodHound up
  • analyze BloodHound data
  • find a path
  • shortest path
  • path to Domain Admin
  • path to DA
  • path to Tier Zero
  • show BloodHound exposure
  • inspect this BloodHound result
  • run a BloodHound query

Route to instead

  • Use $bloodhound-ad-analysis when the user clearly means AD/ADCS pathing such as DCSync, ESC paths, Domain Admins, trusts, sessions, or GPO/ACL abuse.
  • Use $bloodhound-query when the user explicitly wants Cypher written, reviewed, optimized, explained, or adapted from saved queries.
  • Use $azurehound-analysis, $openhound-github, $openhound-jamf, or $openhound-okta when the graph domain is explicit.
  • Use $bloodhound-opengraph when the task is about custom node schemas, ingestors, or graph-model extension work.

Required context

  • Confirm the assessment or lab is authorized and in scope.
  • Confirm bloodhound_mcp is configured and visible in /mcp before relying on live MCP tools.
  • If MCP is unavailable, produce a query/workflow plan instead of claiming live graph facts. The repo includes optional MCP packaging for target environments, but repository work should not install or sync it into the current Codex config unless explicitly requested.
  • Route domain-specific query work to $bloodhound-query, $bloodhound-ad-analysis, $azurehound-analysis, $openhound-github, $openhound-jamf, or $openhound-okta as appropriate.

Default workflow

  1. Check data quality first
    • Start with data_quality(info_type="stats") or data_quality(info_type="platform_list").
    • Call out collection gaps before drawing conclusions.
  2. Find the right graph objects
    • Use domain_info(info_type="list") and domain_info(info_type="search", query=...).
    • Capture object IDs/names for every critical claim.
  3. Use the right composite tool before custom Cypher
    • Prefer user_info, group_info, computer_info, ou_info, gpo_info, graph_analysis, and adcs_info for common questions.
    • Use cypher_query(info_type="run", query=...) only when the composite tools cannot answer cleanly.
  4. Load references before writing attack queries
    • For custom query work, read ../../references/docs/bloodhound-query-methodology.md.
    • For attack scenarios, use the relevant domain index in ../../references/query-indexes/ and adapt a known-good snapshot pattern.
    • For OpenGraph collector, SCIM, or hybrid identity work, also read ../../references/docs/collector-source-index.md, ../../references/docs/scim-methodology.md, ../../references/docs/opengraph-extension-management.md, and ../../references/examples/ as relevant.
    • If MCP exposes live BloodHound resources such as bloodhound://cypher/reference, use them as live supplements, not replacements for the repo-packaged guidance.
  5. Produce assessment-ready output
    • Separate confirmed graph facts from inferred risk.
    • Include affected entities, edge sequence, confidence, data-quality caveats, and remediation.
Show full SKILL.md (143 more words)Show less

Safety and quality rules

  • Do not perform write actions such as custom node changes, asset group changes, saved query edits, or file uploads without explicit user confirmation.
  • Use pagination (limit, skip) for broad queries.
  • Never label a user, computer, or path as low risk without checking memberships, enabled/admincount status, and relevant edge context.
  • Use uppercase names with domain suffixes when filtering BloodHound names, and lowercase property names such as hasspn, enabled, and admincount.
  • Prefer remediation-focused wording over exploitation instructions unless the user explicitly asks for operator guidance in an authorized assessment.

References

  • Read references/bloodhound-mcp-tools.md for the expected MCP tool and resource surface.
  • Read ../../references/docs/source-index.md for official docs, collector references, examples, and vendored query indexes.
  • Use $bloodhound-query for cross-domain query authoring/review.
  • Use $bloodhound-ad-analysis, $azurehound-analysis, $openhound-github, $openhound-jamf, or $openhound-okta for domain-specific saved-query adaptation.
  • Use $bloodhound-opengraph for custom node schema, OpenGraph modeling, and ingestor extension work.

© SpecterOps, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references, assets) in plugins/bloodhound/skills/bloodhound-analysis of SpecterOps/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/icon.png
  • assets/icon.svg
  • references/bloodhound-mcp-tools.md

Open the folder on GitHubat commit e655f93

Compare with similar skills

Bloodhound Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bloodhound Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bloodhound Analysis this skillSpecterOps/skills704—~1.4kAutomated safety check: PassMIT
Openbb Data Fetchermonarchjuno/vibe-investing299—~2.9kAutomated safety check: NotesMIT
Odoo Data Quality Gateerpipe-org/mcp-odoo421—~765Automated safety check: PassMIT
Diagnosekbanc85/claudia296—~1.8kAutomated safety check: PassCustom licence
Erd Studio Setupliam-machine/erd-studio165—~8.5kAutomated safety check: PassCustom licence
Tushare Plugin BuilderYourdaylight/stock_datasource189—~2.5kAutomated safety check: PassMIT

Similar skills

  • Openbb Data Fetcher

    monarchjuno/vibe-investing

    Fetch financial, market, economic, fundamental, news, options, crypto, ETF, index, and macro data through the OpenBB Python interface instead of the OpenBB MCP server.

    299 GitHub stars~2.9k tokensUpdated 5 mo ago
    Data & AnalyticsAuto-check: notes
  • Odoo Data Quality Gate

    erpipe-org/mcp-odoo

    Audit an Odoo database's data quality with evidence before trusting AI answers, importing, or migrating — duplicates, missing required values, orphaned references, format anomalies — and drive…

    421 GitHub stars~765 tokensUpdated 1 mo ago
    Data & AnalyticsAuto-check passed
  • Diagnose

    kbanc85/claudia

    Check memory system health and troubleshoot connectivity issues.

    296 GitHub stars~1.8k tokensUpdated 1 mo ago
    Data & AnalyticsAuto-check passed
  • Erd Studio Setup

    liam-machine/erd-studio

    Friendly, step-by-step setup for ERD Studio in an existing dbt project, for people who may be new to dbt or data modelling.

    165 GitHub stars~8.5k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Tushare Plugin Builder

    Yourdaylight/stock_datasource

    Turns a Tushare API doc URL into a full data plugin for the stock_datasource repo: extractor, ClickHouse schema, query service, config and curl examples.

    189 GitHub stars~2.5k tokensUpdated 1 mo ago
    Data & AnalyticsAuto-check passed
  • Setup Timescaledb Hypertables

    timescale/pg-aiguide

    A skill your agent uses when creating database schemas or tables for Timescale, TimescaleDB, TigerData, or Tiger Cloud, especially for time-series, IoT, metrics, events, or log data.

    1.9k GitHub stars~4.7k tokensUpdated 2 days ago
    Data & AnalyticsAuto-check passed

More from SpecterOps/skills

All 38 skills in this repo
  • Codex Activity Report

    SpecterOps/skills

    Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts.

    704 GitHub stars~805 tokensUpdated 16 days ago
    Auto-check passed
  • Com Proxy Triage

    SpecterOps/skills

    A skill your agent uses when the user wants to triage Windows COM proxy/hijack candidates by capturing HKCU\Software\Classes\CLSID\{...}\InProcServer32 NAME NOT FOUND lookups for a process, mapping…

    704 GitHub stars~1.5k tokensUpdated 16 days ago
    Auto-check passed
  • Cwe Code Review

    SpecterOps/skills

    Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…

    704 GitHub stars~2.4k tokensUpdated 16 days ago
    Auto-check passed
  • Ghostwriter Oplog

    SpecterOps/skills

    A skill your agent uses for Ghostwriter operation log entries from Codex, including config guidance, quick notes, evidence-backed entries, and guided oplog capture through the Ghostwriter MCP tools.

    704 GitHub stars~665 tokensUpdated 16 days ago
    Auto-check passed
  • Nmap Parse

    SpecterOps/skills

    Parse nmap scan output and generate actionable recon notes. An agent skill from SpecterOps/skills.

    704 GitHub stars~738 tokensUpdated 16 days ago
    Auto-check passed
  • Osint Recon

    SpecterOps/skills

    Perform OSINT and external reconnaissance for approved targets.

    704 GitHub stars~813 tokensUpdated 16 days ago
    Auto-check passed

Questions about Bloodhound Analysis

What does Bloodhound Analysis do?

Use as the default router for generic BloodHound asks: check the BloodHound connection, verify MCP health, analyze BloodHound data, find or explain a path, inspect shortest paths, find a path to…. Bloodhound Analysis is an agent skill from SpecterOps/skills. Use as the default router for generic BloodHound asks: check the BloodHound connection, verify MCP health, analyze BloodHound data, find or explain a path, inspect shortest paths, find a path to Domain Admin or Tier Zero, show exposure, run a BloodHound query, or triage graph results when the domain is not yet clear.

When should I use Bloodhound Analysis?

Bloodhound Analysis fits situations like: unrelated network recon; for domain-specific work that is clearly AzureHound; openGraph schema design; explicit Cypher authoring/review.

How do I install Bloodhound Analysis in Claude Code?

Run `npx skills add SpecterOps/skills --skill bloodhound-analysis -a claude-code`. Or copy the skill folder (plugins/bloodhound/skills/bloodhound-analysis in SpecterOps/skills) into .claude/skills/bloodhound-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Bloodhound Analysis in Codex?

Run `npx skills add SpecterOps/skills --skill bloodhound-analysis -a codex`. Or copy the skill folder (plugins/bloodhound/skills/bloodhound-analysis in SpecterOps/skills) into .agents/skills/bloodhound-analysis in your project. Codex loads it when a task matches its description.

Can I use Bloodhound Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SpecterOps/skills --skill bloodhound-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bloodhound-analysis, .gemini/skills/bloodhound-analysis, .github/skills/bloodhound-analysis and .opencode/skills/bloodhound-analysis in your project.

What does Bloodhound Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Bloodhound Analysis is instructions for the agent only.

Does Bloodhound Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Bloodhound Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bloodhound Analysis use?

Bloodhound Analysis is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bloodhound Analysis use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 441 tokens, read only when the agent opens those files.

What are the alternatives to Bloodhound Analysis?

Skills that share tags, products or a category with Bloodhound Analysis: Openbb Data Fetcher (monarchjuno/vibe-investing, 299 stars), Odoo Data Quality Gate (erpipe-org/mcp-odoo, 421 stars), Diagnose (kbanc85/claudia, 296 stars) and Erd Studio Setup (liam-machine/erd-studio, 165 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bloodhound Analysis?

SpecterOps (a GitHub organization) maintains it in SpecterOps/skills, which has 704 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on September 23, 2026.

Source: SpecterOps/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.