disabled-c2-policy

Enforce policy boundaries for command-and-control activity in pentest engagements.

Updated Jul 30, 2026
One-click install
npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill disabled-c2-policy
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: disabled-c2-policy
Source: https://github.com/salmanabdurrahman/pi-pentest-agent/tree/main/skills/disabled-c2-policy
Command: npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill disabled-c2-policy

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill prevents unauthorized or high-risk command-and-control (C2) infrastructure deployment by providing a clear policy-based refusal and routing users toward safer defensive alternatives.

Core Features & Use Cases

  • Policy Enforcement: Automatically identifies and blocks requests for C2 infrastructure setup, beaconing, or evasion techniques.
  • Defensive Routing: Redirects users to legitimate security activities like detection engineering, egress control reviews, and purple-team tabletop exercises.
  • Use Case: When a user asks how to configure a C2 listener, this skill intervenes to explain the policy, verify authorization requirements, and suggest analyzing detection gaps instead.

Quick Start

Ask the agent to explain the policy regarding command and control infrastructure to understand the required authorization gates and safer alternatives.

Frequently Asked Questions about disabled-c2-policy

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enforce policy boundaries for C2 infrastructure during authorized pentest engagements?

To enforce C2 policy boundaries, this skill automatically blocks high-risk command-and-control infrastructure requests and requires explicit repository configuration, engagement-specific consent, and valid authorization metadata before unlocking any workflows.

What happens if I ask an agent how to configure a C2 listener or set up beaconing?

When you request C2 listener configuration or beaconing techniques, the skill intervenes to explain the strict refusal policy, verifies your authorization metadata, and routes you toward analyzing detection gaps instead.

Can I use this skill for offensive security operations like evasion technique deployment?

No, you cannot use this skill for offensive evasion technique deployment. It explicitly refuses high-risk infrastructure requests and redirects authorized pentest engagements toward defensive alternatives like egress control reviews and purple-team tabletop exercises.

Do I need explicit consent and repository configuration to unlock C2 policy workflows?

Yes, unlocking any C2 policy workflows requires explicit repository configuration, engagement-specific consent, and valid authorization metadata to ensure strict governance over command-and-control activity within authorized pentest boundaries.

What defensive alternatives does the policy suggest instead of deploying C2 infrastructure?

Instead of deploying C2 infrastructure, the policy routes you to defensive alternatives including detection engineering, egress control reviews, purple-team tabletop exercises, and architecture review to promote secure boundaries.