PreToolUse
01Hook Claude Code
Runs before the agent uses a tool for Edit, Write, MultiEdit, NotebookEdit and Bash tool calls, executing pre_tool_use_arch_gate.py via python3. From MythicAgents/sage.
Hook Claude Code
Runs before the agent uses a tool for Edit, Write, MultiEdit, NotebookEdit and Bash tool calls, executing pre_tool_use_arch_gate.py via python3. From MythicAgents/sage.
Hook Claude Code
Runs when the agent finishes a response, executing check_arch_budget.py and retention_guard.py via python3 with --quiet, --changed and --warn-only (2 commands). From MythicAgents/sage.
Hook Claude Code
Runs when a subagent finishes, executing retention_guard.py via python3. From MythicAgents/sage.
Settings file Claude Code
Agent settings declaring 3 hook events (PreToolUse, Stop, SubagentStop).
Instructions file CodexOpenCode
AGENTS.md instructions for MythicAgents/sage, covering sage codex session guide, start here, product contracts and runtime authority, durable artifact retention and sealed evaluation review discipline.
Instructions file
Claude Code instructions for MythicAgents/sage, covering sage assistant compatibility guide, current system, required workflows, hard boundaries and testing.
Skill Claude CodeCodex
Analyze Sage's Phoenix/OpenInference trace database (phoenix.db) for the Sage LangGraph multi-agent system. Inspect the latest run, per-model-call token usage, errors, tool-call frequency, and compare two traces (e.g. before/after a context/token optimization). Use when asked to read the Phoenix DB, check Sage trace…
Skill Claude CodeCodex
Sage architecture governance workflow and deterministic edit gate. Use when Codex is asked to change Sage autonomous execution, prompts, LangGraph harness code, tool lists, engagement state/gating, reconcilers, capability planning/adapters, trajectory learning, eval harnesses, live-run drivers, or any multi-step Sage…
Skill Claude CodeCodex
Preserve high-value Sage contracts, handoffs, reviews, transcripts, and evidence in a private project-local history while keeping payloads, credentials, locks, fixtures, clones, and other scratch work temporary.
Skill Claude CodeCodex
Repo-local post-Mythic-reset Sage chat and foothold bootstrap workflow. Use to verify the Sage chat container, create or restore Apollo/Merlin footholds, check readiness, or rediscover the live CASTELBLACK callback.
Skill Claude CodeCodex
Independently attest a bounded native Mythic canary by reconstructing the run from Mythic's own records with a read-only Spectator credential, then diffing those records against the frozen conversation-case expected trace. Use after a native canary run to decide whether the kernel behaved, without trusting the…
Skill Claude CodeCodex
Run repeated real-model perturbation trials against Sage's frozen conversation-control constitution and report pass^k, forbidden events, duplicate events, terminal correctness, and provider provenance.
Skill Claude CodeCodex
Repo-local Sage eval-gauge / hill-climbing Phase-0 toolkit. Use when an operator, Claude Code, or Codex needs to measure Sage capability with a GROUND-TRUTHED gauge (not substring eval scores), run the Gate Experiment (does the eval track reality?), compare bare-model vs harness, get the noise floor /…
Skill Claude CodeCodex
Repo-local focused Sage capability, adapter, and notification validation workflow. Use when Codex, Claude Code, or an operator needs to smoke-test one generic capability, validate a Mythic capability adapter path, reproduce a focused ADCS/DCSync/GPO/LAPS/Kerberos behavior, test the fixed-content Slack findings hook…
Skill Claude CodeCodex
Rebuild a live Apollo foothold on the GOAD range as NORTH\samwell.tarly with NO operator, NO RDP client, and NO X display — a pure WinRM scheduled-task (batch-logon) launch. Use to reset the range and re-establish a foothold end to end unattended (headless agent or cron), or to launch a foothold against an…
Skill Claude CodeCodex
Repo-local Sage Forge/Codex helper workflow. Use when Codex, Claude Code, or an operator needs to run Sage-specific Forge helper automation or preserve Forge operational scripts outside Plans.
Skill Claude CodeCodex
Repo-local Sage GOAD/Trust Walker full lab reset and readiness workflow. Use when Codex, Claude Code, or an operator asks to reset everything, perform a full reset, archive Sage/Phoenix runtime databases, reset Docker-backed Mythic, reset or verify Ludus GOAD, wipe/check BloodHound CE, restart local Sage safely…
Skill Claude CodeCodex
Repo-local Sage native Mythic v4 chat execution and inspection workflow. Use for strict one-shot GOAD solves, chat readiness probes, channel/request monitoring, or legacy payload-task diagnosis.
Skill Claude CodeCodex
Download an existing Mythic payload, stage it onto a Ludus Windows host over WinRM, and launch it as the current user or a supplied run-as user. Use when Codex needs to redeploy an Apollo/Sage/Mythic payload after Mythic has already built it, recover a dead GOAD callback without resetting Mythic, or help create a…
Skill Claude CodeCodex
Repo-local Sage trace, Phoenix, Mythic task-output, and run-log analysis workflow. Use when Codex, Claude Code, or an operator needs to mine historical failures, inspect Phoenix spans, backfill task IDs, audit solve steps, or diagnose ingestion/file/output behavior without creating new Plans tools.
Skill Claude CodeCodex
Repo-local Sage trajectory learning workflow. Use when Codex, Claude Code, or an operator needs to inventory retained Sage/Phoenix/run-log artifacts, export normalized state-action-observation-verifier-repair transition records, label repeated blocker classes, replay repair-policy decisions, or process historical DB…