hexstrike-forge
Installation
SKILL.md
HexStrike Forge
HexStrike executes. Rifteo refines. This skill sequences HexStrike tools intelligently, filters noise down to confirmed findings, and assembles a professional report.
Rule: No exploit, no finding. Every HexStrike output is a hypothesis until triage confirms it.
Startup
1. Scope gate
Run scope-grill skill if installed (npx rifteo-skills add scope-grill to install). If not installed, ask these three questions before any active testing and do not proceed until all are answered:
- Do you have written authorization to test this target?
- What is in scope and what is explicitly out of scope?
- Any restrictions? (no DoS, time windows, excluded hosts?)
If authorization cannot be confirmed, stop. Do not proceed.
2. Tool pre-check
Call server_health. Diff available tools against the phases in references/tool-sequences.md for the identified target type. Note any capability gaps upfront — do not discover them mid-engagement.