redteam-mindset

Structure red-team testing with decision trees and anti-pattern flags.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/pdparchitect/rook --skill redteam-mindset-pdparchitect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: redteam-mindset
Source: https://github.com/pdparchitect/rook/tree/main/skills/redteam-mindset
Command: npx skills add https://github.com/pdparchitect/rook --skill redteam-mindset-pdparchitect

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill addresses the common failure modes in offensive security engagements where operators self-throttle, prematurely retract findings, or fail to exhaust the attack surface due to a lack of structured, aggressive methodology.

Core Features & Use Cases

  • Decision Frameworks: Provides clear directives on when to continue testing versus when to stop, preventing premature engagement closure.
  • Anti-Pattern Identification: Explicitly flags behaviors like mid-engagement permission seeking, failure to test sister applications, and improper handling of WAF/IR interference.
  • Operational Cadence: Defines the standard for a complete, professional sweep of live hosts, ensuring no attack surface is left unprobed.

Quick Start

Load the redteam-mindset skill to establish the operational rules and decision-making framework for your current authorized red-team engagement.

Frequently Asked Questions about redteam-mindset

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I maintain operational discipline during a red-team engagement?

Maintain operational discipline in red-team engagements by applying a structured decision framework that dictates when to continue testing versus stopping, preventing premature engagement closure. This methodology ensures systematic attack surface coverage and rigorous finding validation.

Why do operators prematurely retract findings during offensive security testing?

Operators prematurely retract findings during offensive security testing due to a lack of structured, aggressive methodology. This anti-pattern is addressed by defining clear decision trees for blockers and requiring multi-technique cross-validation of vulnerabilities.

How do I ensure complete attack surface coverage during authorized pentesting?

Ensure complete attack surface coverage during pentesting by following a defined operational cadence that guarantees a professional sweep of all live hosts. This framework mandates sister-app pattern recognition to prevent leaving any target unprobed.

What is the best way to handle WAF or IR interference during a red team operation?

Handle WAF or IR interference during a red team operation by adhering to defined decision trees for blockers. This anti-pattern identification ensures operators maintain aggressive testing discipline instead of self-throttling when faced with defensive interference.

Does this red-team methodology apply to vulnerability auditing on specific platforms?

Yes, this red-team methodology applies to authorized offensive security engagements and vulnerability auditing across any platform. It requires adherence to defined decision trees for blockers and multi-technique cross-validation to ensure rigorous finding validation.

When should I avoid self-throttling behaviors in offensive security engagements?

Avoid self-throttling behaviors in offensive security engagements whenever you face mid-engagement blockers. The framework explicitly flags improper behaviors like mid-engagement permission seeking and failure to test sister applications to ensure aggressive testing continues.