crown-jewel

Identify high-value business impact objectives and prioritize attack surfaces for offensive security engagements.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill crown-jewel
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: crown-jewel
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/meta/crown-jewel
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill crown-jewel

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill solves the problem of aimless, generic security scanning by forcing a strategic focus on the highest-value business impacts before any technical testing begins.

Core Features & Use Cases

  • Impact-Driven Prioritization: Maps business models to specific crown-jewel assets and high-yield attack surfaces.
  • Strategic Workflow Routing: Provides a structured decision loop to transition from target identification to specific attack modes like deep-hunts or chain-building.
  • Use Case: When starting a new bug bounty engagement for a fintech platform, use this skill to identify that money movement and invoice data are the primary objectives, allowing you to focus your recon on webhooks and ledger endpoints rather than generic surface area.

Quick Start

Invoke the crown-jewel skill by providing the target domain or program name to generate a prioritized attack plan and dossier path.

Frequently Asked Questions about crown-jewel

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I identify high-impact targets for bug bounty and pentest engagements?

To identify high-impact targets for bug bounty and pentest engagements, you map the target's business model to specific crown-jewel assets. This impact-driven prioritization aligns technical testing with critical business logic vulnerabilities instead of generic surface scanning.

What is threat modeling for crown-jewel assets in offensive security?

Threat modeling for crown-jewel assets in offensive security is the process of mapping business models to high-value objectives like money movement or invoice data. It prioritizes attack surfaces to focus deep-hunts on critical business logic vulnerabilities.

How do I prioritize attack surfaces for red team workflows?

You prioritize attack surfaces for red team workflows by providing target context, such as a domain or program name, to generate a structured decision loop. This transitions target identification into specific attack modes like chain-building and deep-hunts.

Can I use business logic mapping for fintech bug bounty recon?

Yes, you can use business logic mapping for fintech bug bounty recon to identify primary objectives like money movement and invoice data. This directs your recon toward high-yield endpoints such as webhooks and ledgers rather than generic surface area.

Does this approach require target context to map business models effectively?

Yes, this approach requires target context to map business models effectively. Providing the target domain or program name is necessary to generate a prioritized attack plan and accurately route specific offensive security attack modes.

Why should I avoid generic security scanning during offensive security engagements?

You should avoid generic security scanning during offensive security engagements because it lacks strategic focus. Mapping business models to crown-jewel assets first ensures technical testing targets high-value business impacts, yielding higher severity vulnerabilities.