redteam-mindset

Enforce authorization, scope, and technical probing discipline for red team engagements.

5|Updated May 27, 2026
One-click install
npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill redteam-mindset-cybersecwoman
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: redteam-mindset
Source: https://github.com/cybersecwoman/Kiro-BugHunter/tree/main/skills/redteam-mindset
Command: npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill redteam-mindset-cybersecwoman

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the mindset and discipline needed for successful red team engagements, distinguishing offensive testing from defensive WAPT.

Core Features & Use Cases

  • Mindset Correction: Offers guidance on mindset shifts critical for red team operations.
  • Engagement Discipline: Provides rules for engagement scope, authorization, and discipline.
  • Technical Guidance: Offers techniques for handling blockers like captchas, WAFs, and rate limits.
  • Use Case: Use this Skill to ensure a comprehensive and effective red team engagement, especially in external red team scenarios.

Quick Start

Load the redteam-mindset skill at the start of any red team engagement to establish the correct mindset and discipline.

Frequently Asked Questions about redteam-mindset

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the difference between red team and bug bounty scope?

Red team engagements require strict authorization and scope discipline, whereas bug bounty programs operate under broader platform guidelines. This distinction ensures offensive testing remains compliant with specific client boundaries.

How do I maintain engagement discipline during external red team operations?

Maintain engagement discipline by adhering to specific authorization rules and scope boundaries. Establishing the correct red team mindset at the start ensures offensive testing stays within approved operational limits.

How do red teams bypass WAFs and rate limits during offensive testing?

Red teams handle blockers like WAFs and rate limits using specific technical probing techniques. These methods are part of operational discipline focused on authorized vulnerability assessment.

Does this red team guidance apply to defensive WAPT?

This guidance specifically distinguishes offensive red team testing from defensive WAPT. It provides mindset corrections and operational discipline exclusively for authorized offensive testing scenarios.

When do I need to load red team mindset rules for a security assessment?

Load red team mindset rules at the start of any authorized engagement. This establishes operational discipline and scope adherence before initiating technical probing and vulnerability assessment.