redteam-mindset

Enforce red team scope, stop/escalation rules, and per-host cadence for extended assessments.

1|Updated May 25, 2026
One-click install
npx skills add https://github.com/ctahok/hermes-bug-bounty-skills --skill redteam-mindset-ctahok
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: redteam-mindset
Source: https://github.com/ctahok/hermes-bug-bounty-skills/tree/main/redteam-mindset
Command: npx skills add https://github.com/ctahok/hermes-bug-bounty-skills --skill redteam-mindset-ctahok

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps you plan and execute extended security engagements consistently by clarifying how red team objectives differ from bug bounty or WAPT goals, and by enforcing discipline that preserves correctness and authorization boundaries.

Core Features & Use Cases

  • Authorization permanence guidance: Keeps decision-making aligned with the engagement’s scope across the full runtime.
  • Stop/escalation decision rules: Prevents self-throttling mistakes while ensuring you don’t over-escalate within a confirmed finding’s boundaries.
  • Per-host cadence and marker discipline: Establishes minimum recon/checklists and payload marker practices to keep results attributable and reproducible.

Quick Start

Use the redteam-mindset skill to align your testing workflow with authorization rules, identify anti-patterns that invalidate findings, and define a per-host engagement cadence before you start an extended assessment.

Frequently Asked Questions about redteam-mindset

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I maintain authorization scope during an extended red team engagement?

To maintain authorization scope during a red team engagement, use authorization permanence guidance to keep decisions aligned with boundaries across the full runtime. This prevents scope drift and avoids anti-patterns that invalidate findings.

What is the difference between red team testing and bug bounty scope?

Red team testing differs from bug bounty scope by focusing on extended multi-day host assessments with disciplined execution rather than isolated vulnerability collection. It enforces per-host cadence, marker discipline, and stop/escalation behavior.

How do I establish a per-host testing cadence for multi-day security assessments?

Establish a per-host testing cadence by defining minimum recon checklists and applying payload marker discipline before starting extended host assessments. This ensures results remain attributable and reproducible.

When should I escalate or stop testing during a red team engagement?

Apply stop/escalation decision rules during a red team engagement to prevent self-throttling mistakes while ensuring you do not over-escalate beyond a confirmed finding's authorization boundaries.

What evidence hygiene practices do I need for red team engagement marker discipline?

Evidence hygiene for red team engagements requires payload markers to keep test results attributable and reproducible. Marker discipline ensures findings are correctly attributed to your testing cadence.