opfor-run

Installation
SKILL.md

Opfor — assessment execution

Execute an Opfor assessment using pre-generated attack inputs. The /opfor-setup skill generates all attack variations beforehand; this skill executes them, judges responses, and generates a report.

Prerequisites: A config folder created by /opfor-setup at .opfor/configs/<uuid>/

Note: This skill uses:

  • ../opfor-setup/targets/<target-type>.md — target adapters (how to send requests)
  • Pre-generated attack inputs from .opfor/configs/<uuid>/inputs/ — crafted by config

Source-scan evaluators (whitebox) — on by default: Some evaluators are whitebox (scan_mode: source_code in the catalog, e.g. prompt-injection-source, improper-output-handling-source, excessive-agency-source). They read the agent's source instead of sending a prompt. The Static Source Pre-Scan (Step 3.5) runs by default — assume the assessment is on a codebase. Run every source-scan evaluator in the suite whenever a source root is resolvable, even if the loaded config did not explicitly list them, then Correlate (Step 5.5) after judging. The static pass is not a setting and is never asked about — the only consent prompt is for optionally running an external scanner (semgrep/codeql) in Step 3.5c. Skip Steps 3.5/5.5 only when no source root can be resolved (e.g. a remote http-endpoint with no repo path); then record those evaluators as dynamic-only and continue.


1. Load Config Folder

Scan .opfor/configs/ for UUID-named subdirectories (each contains config.md).

Installs
8
GitHub Stars
422
First Seen
Jun 25, 2026
opfor-run — keyvaluesoftwaresystems/agent-opfor