MythicAgents

21 mods across 1 repository, 21 stars between them.

PreToolUse

01

MythicAgents/sage

Hook Claude Code

Runs before the agent uses a tool for Edit, Write, MultiEdit, NotebookEdit and Bash tool calls, executing pre_tool_use_arch_gate.py via python3. From MythicAgents/sage.

21 6d ago A tokens not measured GPL-3.0

Stop

02

MythicAgents/sage

Hook Claude Code

Runs when the agent finishes a response, executing check_arch_budget.py and retention_guard.py via python3 with --quiet, --changed and --warn-only (2 commands). From MythicAgents/sage.

21 6d ago A tokens not measured GPL-3.0

SubagentStop

03

MythicAgents/sage

Hook Claude Code

Runs when a subagent finishes, executing retention_guard.py via python3. From MythicAgents/sage.

21 6d ago A tokens not measured GPL-3.0

sage

04

MythicAgents/sage

Settings file Claude Code

Agent settings declaring 3 hook events (PreToolUse, Stop, SubagentStop).

21 6d ago A tokens not measured GPL-3.0

sage AGENTS.md

05

MythicAgents/sage

Instructions file CodexOpenCode

AGENTS.md instructions for MythicAgents/sage, covering sage codex session guide, start here, product contracts and runtime authority, durable artifact retention and sealed evaluation review discipline.

21 6d ago A 10,388 tokens GPL-3.0

sage CLAUDE.md

06

MythicAgents/sage

Instructions file

Claude Code instructions for MythicAgents/sage, covering sage assistant compatibility guide, current system, required workflows, hard boundaries and testing.

21 6d ago A 1,299 tokens GPL-3.0

phoenix-traces

07

MythicAgents/sage

Skill Claude CodeCodex

Analyze Sage's Phoenix/OpenInference trace database (phoenix.db) for the Sage LangGraph multi-agent system. Inspect the latest run, per-model-call token usage, errors, tool-call frequency, and compare two traces (e.g. before/after a context/token optimization). Use when asked to read the Phoenix DB, check Sage trace…

21 6d ago A 97 tokens GPL-3.0

MythicAgents/sage

Skill Claude CodeCodex

Sage architecture governance workflow and deterministic edit gate. Use when Codex is asked to change Sage autonomous execution, prompts, LangGraph harness code, tool lists, engagement state/gating, reconcilers, capability planning/adapters, trajectory learning, eval harnesses, live-run drivers, or any multi-step Sage…

21 6d ago A 95 tokens GPL-3.0

MythicAgents/sage

Skill Claude CodeCodex

Preserve high-value Sage contracts, handoffs, reviews, transcripts, and evidence in a private project-local history while keeping payloads, credentials, locks, fixtures, clones, and other scratch work temporary.

21 6d ago A 47 tokens GPL-3.0

MythicAgents/sage

Skill Claude CodeCodex

Repo-local post-Mythic-reset Sage chat and foothold bootstrap workflow. Use to verify the Sage chat container, create or restore Apollo/Merlin footholds, check readiness, or rediscover the live CASTELBLACK callback.

21 6d ago A 52 tokens GPL-3.0

MythicAgents/sage

Skill Claude CodeCodex

Independently attest a bounded native Mythic canary by reconstructing the run from Mythic's own records with a read-only Spectator credential, then diffing those records against the frozen conversation-case expected trace. Use after a native canary run to decide whether the kernel behaved, without trusting the…

21 6d ago A 70 tokens GPL-3.0

MythicAgents/sage

Skill Claude CodeCodex

Run repeated real-model perturbation trials against Sage's frozen conversation-control constitution and report pass^k, forbidden events, duplicate events, terminal correctness, and provider provenance.

21 6d ago A 38 tokens GPL-3.0

sage-eval-gauge

13

MythicAgents/sage

Skill Claude CodeCodex

Repo-local Sage eval-gauge / hill-climbing Phase-0 toolkit. Use when an operator, Claude Code, or Codex needs to measure Sage capability with a GROUND-TRUTHED gauge (not substring eval scores), run the Gate Experiment (does the eval track reality?), compare bare-model vs harness, get the noise floor /…

21 6d ago A 108 tokens GPL-3.0

MythicAgents/sage

Skill Claude CodeCodex

Repo-local focused Sage capability, adapter, and notification validation workflow. Use when Codex, Claude Code, or an operator needs to smoke-test one generic capability, validate a Mythic capability adapter path, reproduce a focused ADCS/DCSync/GPO/LAPS/Kerberos behavior, test the fixed-content Slack findings hook…

21 6d ago A 83 tokens GPL-3.0

MythicAgents/sage

Skill Claude CodeCodex

Rebuild a live Apollo foothold on the GOAD range as NORTH\samwell.tarly with NO operator, NO RDP client, and NO X display — a pure WinRM scheduled-task (batch-logon) launch. Use to reset the range and re-establish a foothold end to end unattended (headless agent or cron), or to launch a foothold against an…

21 6d ago B 120 tokens GPL-3.0

sage-forge-ops

16

MythicAgents/sage

Skill Claude CodeCodex

Repo-local Sage Forge/Codex helper workflow. Use when Codex, Claude Code, or an operator needs to run Sage-specific Forge helper automation or preserve Forge operational scripts outside Plans.

21 6d ago A 43 tokens GPL-3.0

sage-goad-reset

17

MythicAgents/sage

Skill Claude CodeCodex

Repo-local Sage GOAD/Trust Walker full lab reset and readiness workflow. Use when Codex, Claude Code, or an operator asks to reset everything, perform a full reset, archive Sage/Phoenix runtime databases, reset Docker-backed Mythic, reset or verify Ludus GOAD, wipe/check BloodHound CE, restart local Sage safely…

21 6d ago B 104 tokens GPL-3.0

sage-live-runner

18

MythicAgents/sage

Skill Claude CodeCodex

Repo-local Sage native Mythic v4 chat execution and inspection workflow. Use for strict one-shot GOAD solves, chat readiness probes, channel/request monitoring, or legacy payload-task diagnosis.

21 6d ago A 42 tokens GPL-3.0

MythicAgents/sage

Skill Claude CodeCodex

Download an existing Mythic payload, stage it onto a Ludus Windows host over WinRM, and launch it as the current user or a supplied run-as user. Use when Codex needs to redeploy an Apollo/Sage/Mythic payload after Mythic has already built it, recover a dead GOAD callback without resetting Mythic, or help create a…

21 6d ago B 104 tokens GPL-3.0

sage-trace-analysis

20

MythicAgents/sage

Skill Claude CodeCodex

Repo-local Sage trace, Phoenix, Mythic task-output, and run-log analysis workflow. Use when Codex, Claude Code, or an operator needs to mine historical failures, inspect Phoenix spans, backfill task IDs, audit solve steps, or diagnose ingestion/file/output behavior without creating new Plans tools.

21 6d ago A 65 tokens GPL-3.0

MythicAgents/sage

Skill Claude CodeCodex

Repo-local Sage trajectory learning workflow. Use when Codex, Claude Code, or an operator needs to inventory retained Sage/Phoenix/run-log artifacts, export normalized state-action-observation-verifier-repair transition records, label repeated blocker classes, replay repair-policy decisions, or process historical DB…

21 6d ago A 69 tokens GPL-3.0