Agent skill

Regression Sweep

by transilienceai in transilienceai/communitytools

Re-validates every previously-confirmed finding against its current target — detects drift (patched, mitigated, re-introduced).

MITAuto-check passedProductivity & Automation

Install Regression Sweep

skills CLI
$ npx skills add transilienceai/communitytools --skill regression-sweep -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install transilienceai/communitytools regression-sweep --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/transilienceai/communitytools.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/regression-sweep .claude/skills/regression-sweep && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
regression-sweep
GitHub stars
563
Token cost
~1k tokens
SKILL.md length
370 words
Files
2
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Re-validates every previously-confirmed finding against its current target — detects drift (patched, mitigated, re-introduced).

  • Works in 4 steps: Index validated findings. Glob… → Per finding → Classify each finding into one of → …
  • Tasks that involve Scheduled and recurring tasks
  • SKILL.md covers Trigger, Workflow, Output and Rules, plus 1 more section
  • Calls python3

What it does

Regression Sweep is an agent skill from transilienceai/communitytools. Re-validates every previously-confirmed finding against its current target — detects drift (patched, mitigated, re-introduced). Cron-driven weekly sweep across the org's validated finding tree.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `reference/diff-normalization.md`).

It sits in Productivity & Automation, covering Scheduled and recurring tasks. The repository describes itself as: Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and security research. The licence is MIT.

When your agent uses it

  • Tasks that involve Scheduled and recurring tasks

Example prompts

  • “/regression-sweep”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Index validated findings. Glob validated/*.json and resolve each entry's FINDING_DIR (under findings/finding-NNN/).
  2. Per finding
  3. Classify each finding into one of
  4. Write report to artifacts/regression-{YYYYWww}.json + human-readable regression-{YYYYWww}.md. Transitions (newly_revalidated…

What it can do on your machine

Read from SKILL.md and the folder at commit 95fdc12. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Regression Sweep loads about 1k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 370 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from transilienceai/communitytools at commit 95fdc12, republished under its MIT licence (© transilienceai). 370 words, ~1,028 tokens.

Download SKILL.mdSave it as .claude/skills/regression-sweep/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
regression-sweep
description
Re-validates every previously-confirmed finding against its current target — detects drift (patched, mitigated, re-introduced). Cron-driven weekly sweep across the org's validated finding tree.

Regression Sweep

Walk the entire validated/*.json tree, re-fire each finding's poc.py, compare output against the recorded poc_output.txt, and write a weekly drift report. Mounted onto the cloud-agent task #4.

Trigger

Cron weekly (default Mondays 02:00 UTC). May also be invoked ad-hoc after a major patch deployment.

Workflow

  1. Index validated findings. Glob validated/*.json and resolve each entry's FINDING_DIR (under findings/finding-NNN/).
  2. Per finding:
    • Re-run python3 poc.py with a 60-second timeout.
    • Capture stdout/stderr into findings/finding-NNN/evidence/validation/regression-{week}-rerun.txt.
    • Diff against findings/finding-NNN/evidence/validation/poc-rerun-output.txt (the validator's original re-run output) using a normalized line-set comparison (strip timestamps, request IDs, ephemeral tokens).
    • Re-check the finding's CVE via tools/nvd-lookup.py — has severity changed?
  3. Classify each finding into one of:
    • still_valid — re-run matches baseline within tolerance, CVSS unchanged.
    • drift_severity — re-run matches, but CVSS shifted ≥1.0 (NVD re-scored).
    • newly_invalid — re-run output diverges, exploit no longer fires. Likely patched.
    • newly_revalidated — finding had been marked REJECTED later, but now fires again. Regression.
    • inconclusive — re-run errored (network, target unreachable). Retry next sweep.
  4. Write report to artifacts/regression-{YYYYWww}.json + human-readable regression-{YYYYWww}.md. Transitions (newly_revalidated, drift_severity, newly_invalid) appear in the report under explicit headers for analyst review.

Output

{OUTPUT_DIR}/
  artifacts/
    regression-{YYYYWww}.json         # machine-readable result
    regression-{YYYYWww}.md           # human summary
  findings/finding-NNN/evidence/validation/
    regression-{YYYYWww}-rerun.txt    # captured re-run output

regression-{week}.json schema:

json
{
  "week": "2026W19",
  "swept_at": "2026-05-13T02:00:00Z",
  "counts": {"still_valid": 47, "drift_severity": 2, "newly_invalid": 5, "newly_revalidated": 1, "inconclusive": 3},
  "findings": [
    {"finding_id": "finding-012", "asset": "asset42", "cve": "CVE-2024-12345",
     "verdict": "newly_invalid", "reason": "PoC output diverged: response now 404",
     "baseline_cvss": 9.8, "current_cvss": 9.8}
  ]
}
Show full SKILL.md (189 more words)Show less

Rules

  1. Demonstrate, never disrupt. Re-firing a PoC is observation, not mutation. Every poc.py already satisfied the demonstrate-only constraints at validation time (task-03 Safety section); the sweep simply re-executes the same script — which by contract reads a proof signal and exits. If a PoC at re-run attempts a mutating action it should not have contained originally, the sweep aborts that finding with inconclusive and emits a stderr WARN — the PoC needs re-validation, not regression scoring.
  2. Bounded per-PoC time. 60-second timeout per poc.py. Timeouts → inconclusive, not newly_invalid. Avoids false-positive "patched" claims caused by network blips.
  3. Normalized diff. Strip timestamps (\d{4}-\d{2}-\d{2}T\d{2}:\d{2}), request-IDs ([a-f0-9]{32,}), and ephemeral session tokens before comparing. Real exploit output is structurally stable.
  4. No new findings. A regression sweep can flip status of existing findings but cannot create new ones. Newly observed vulns belong to the Validation Run task, not this skill.
  5. Idempotent. Re-running the same week's sweep overwrites the same regression-{YYYYWww}.json. The per-finding regression-{week}-rerun.txt is timestamped to preserve history.
  6. Cap concurrent re-runs. Max 5 parallel PoC re-runs per sweep to avoid hammering production assets.

References

  • reference/diff-normalization.md — full normalization rules and per-finding output-stability heuristics.

© transilienceai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/regression-sweep of transilienceai/communitytools.

  • SKILL.md
  • reference/diff-normalization.md

Open the folder on GitHubat commit 95fdc12

Compare with similar skills

Regression Sweep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Regression Sweep compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Regression Sweep this skilltransilienceai/communitytools563—~1kAutomated safety check: PassMIT
Ohdearohdearapp/ohdear-cli141—~1.1kAutomated safety check: PassMIT
Alibabacloud Ecs Windows Os Troubleshootingaliyun/alibabacloud-ecs-troubleshoot-skills148—~6.1kAutomated safety check: PassApache-2.0
Hunting For Scheduled Task Persistencemukul975/Anthropic-Cybersecurity-Skills34k—~907Automated safety check: PassApache-2.0
Eradicating Malware From Infected Systemsmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: WarnApache-2.0
ScheduleTinyAGI/tinyagi3.6k—~1.4kAutomated safety check: PassMIT

Similar skills

  • Ohdear

    ohdearapp/ohdear-cli

    Manage Oh Dear website monitoring using the ohdear CLI. An agent skill from ohdearapp/ohdear-cli.

    141 GitHub stars~1.1k tokensUpdated 1 mo ago
    Productivity & AutomationAuto-check passed
  • Alibabacloud Ecs Windows Os Troubleshooting

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Troubleshoot and repair Alibaba Cloud ECS Windows instances from inside the GuestOS or remotely via Cloud Assistant.

    148 GitHub stars~6.1k tokensUpdated 1 mo ago
    Productivity & AutomationAuto-check passed
  • Hunting For Scheduled Task Persistence

    mukul975/Anthropic-Cybersecurity-Skills

    Runs a hypothesis-driven threat hunt for Windows Scheduled Task persistence (T1053), guiding SIEM/EDR queries against task creation events (e.g.

    34k GitHub stars~907 tokensUpdated 1 mo ago
    Productivity & AutomationAuto-check passed
  • Eradicating Malware From Infected Systems

    mukul975/Anthropic-Cybersecurity-Skills

    Systematically map and remove malware, backdoors, and attacker persistence mechanisms (registry Run keys, scheduled tasks, WMI subscriptions, services, cron/init.d) from infected Windows and Linux…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    Productivity & AutomationAuto-check: warnings
  • Schedule

    TinyAGI/tinyagi

    Create, list, and delete scheduled tasks (recurring or one-time) that send messages to agents.

    3.6k GitHub stars~1.4k tokensUpdated 6 mo ago
    Productivity & AutomationAuto-check passed
  • Send User Message

    TinyAGI/tinyagi

    Send a proactive message to a paired user via their channel (Discord, Telegram, or WhatsApp).

    3.6k GitHub stars~829 tokensUpdated 6 mo ago
    Productivity & AutomationAuto-check passed

More from transilienceai/communitytools

All 35 skills in this repo
  • Dfir

    transilienceai/communitytools

    Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

    563 GitHub stars~1.5k tokensUpdated 2 mo ago
    Auto-check passed
  • GitHub Workflow

    transilienceai/communitytools

    GitHub workflow automation — branching, committing, pushing, pull requests, issues, and code review.

    563 GitHub stars~812 tokensUpdated 2 mo ago
    Auto-check: notes
  • Pci Secure Software

    transilienceai/communitytools

    Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation.

    563 GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Protect With Password

    transilienceai/communitytools

    Generate ONE strong password and apply it to each referenced file (PDF, Word, Excel, PowerPoint, or any type).

    563 GitHub stars~583 tokensUpdated 2 mo ago
    Auto-check passed
  • Skill Update

    transilienceai/communitytools

    Skill creation, update and management — generates skill directory structure, validates against best practices, enforces line count limits.

    563 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Source Code Scanning

    transilienceai/communitytools

    Security-focused source code review and SAST. An agent skill from transilienceai/communitytools.

    563 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check: notes

Questions about Regression Sweep

What does Regression Sweep do?

Re-validates every previously-confirmed finding against its current target — detects drift (patched, mitigated, re-introduced). Regression Sweep is an agent skill from transilienceai/communitytools. Re-validates every previously-confirmed finding against its current target — detects drift (patched, mitigated, re-introduced).

When should I use Regression Sweep?

Regression Sweep fits situations like: tasks that involve Scheduled and recurring tasks.

How do I install Regression Sweep in Claude Code?

Run `npx skills add transilienceai/communitytools --skill regression-sweep -a claude-code`. Or copy the skill folder (skills/regression-sweep in transilienceai/communitytools) into .claude/skills/regression-sweep in your project. Claude Code loads it when a task matches its description.

How do I install Regression Sweep in Codex?

Run `npx skills add transilienceai/communitytools --skill regression-sweep -a codex`. Or copy the skill folder (skills/regression-sweep in transilienceai/communitytools) into .agents/skills/regression-sweep in your project. Codex loads it when a task matches its description.

Can I use Regression Sweep in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add transilienceai/communitytools --skill regression-sweep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/regression-sweep, .gemini/skills/regression-sweep, .github/skills/regression-sweep and .opencode/skills/regression-sweep in your project.

What does Regression Sweep need to run?

Going by SKILL.md and its folder, Regression Sweep needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Regression Sweep access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Regression Sweep safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Regression Sweep use?

Regression Sweep is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Regression Sweep use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Regression Sweep?

Skills that share tags, products or a category with Regression Sweep: Ohdear (ohdearapp/ohdear-cli, 141 stars), Alibabacloud Ecs Windows Os Troubleshooting (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars), Hunting For Scheduled Task Persistence (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Eradicating Malware From Infected Systems (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Regression Sweep?

transilienceai (a GitHub organization) maintains it in transilienceai/communitytools, which has 563 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on July 29, 2026.

Source: transilienceai/communitytools on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.