Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/hypnguyen1209/offensive-claudeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/hypnguyen1209/offensive-claude/engage.deliver)<a href="https://agentmods.dev/commands/hypnguyen1209/offensive-claude/engage.deliver"><img src="https://agentmods.dev/badge/commands/hypnguyen1209/offensive-claude/engage.deliver/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/hypnguyen1209/offensive-claude/engage.deliver"><img src="https://agentmods.dev/badge/commands/hypnguyen1209/offensive-claude/engage.deliver.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00009 | $0.00969 |
| Opus 5 | $0.00005 | $0.00485 |
| Sonnet 5 | $0.00002 | $0.00194 |
| Haiku 4.5 | $0.00001 | $0.00097 |
Grade A, and why
engage.deliver scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 163 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/engage.deliver
Executes Phase 3 (Delivery) of the engagement workflow.
Usage
/engage.deliver [--vector <delivery-method>]
Options:
--vector: Specify delivery method (web, email, physical, remote)
Process
1. Load Template
Loads delivery/delivery-plan.md template.
2. Delivery Vector Selection
Reviews weaponization output and prompts:
- What delivery method is authorized per ROE?
- What is the target's attack surface?
- What delivery method has highest success probability?
Delivery Vectors:
- Web: Exploit via HTTP request (direct exploitation)
- Email: Phishing with malicious attachment or link
- Physical: USB drop, physical access
- Remote: Direct network exploitation (SMB, RDP, SSH)
- Supply Chain: Compromise third-party dependency
- Watering Hole: Compromise frequently visited site
3. Delivery Plan
Populates delivery-plan.md with:
Delivery Method:
- Selected vector
- Justification (why this method?)
- Prerequisites (access, credentials, social engineering)
Delivery Mechanism:
- Technical implementation details
- Payload packaging (if applicable)
- Delivery infrastructure (redirectors, domains, servers)
Delivery Execution:
- Step-by-step delivery procedure
- Expected target behavior
- Success indicators
- Failure indicators
OPSEC Considerations:
- Attribution risks
- Detection likelihood
- Cleanup requirements
4. Delivery Execution
Guides through delivery execution:
For Web Delivery:
- Craft HTTP request with exploit payload
- Send request to target
- Monitor for callback or success indicator
For Email Delivery:
- Craft phishing email (if authorized)
- Attach or link to payload
- Send to target
- Monitor for execution
For Remote Delivery:
- Establish network connectivity to target
- Execute exploit against service
- Monitor for callback
5. Delivery Confirmation
Prompts for delivery status:
- Was payload delivered successfully?
- Did target receive/execute payload?
- Any errors or unexpected behavior?
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 163 lines · 9 tokens per session scan A 4c3a5765d8f1
engage.deliver is a command published in the GitHub repository hypnguyen1209/offensive-claude (357 stars, last pushed 24d ago), licensed MIT. It adds 9 tokens to every session and 969 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
discover
Run a full product discovery cycle — from outcome definition through opportunity mapping, prioritisation, and experiment design. Use when the team isn't sure what to build next, or before writing a PRD for a complex feature space.
voice-compliance
Voice/telephony compliance check — invokes voice-ai-reviewer to produce TM-voice-{slug}.md with TCPA, STIR/SHAKEN, state recording-consent, EU AI Act Art. 50, and synth-voice deepfake-law gaps.
claude-tracker
List recent Claude Code sessions with live status.
qa
Smoke or browser-walk a running app. Report only. Do not implement. Do not merge.
esp-harden
Harden and inspect ESP32 firmware for field failures, crashes, memory, and security.
replication-package
Scaffold or audit a social-science replication package at a target directory, and audit the manuscript and its archived research objects against FAIR principles.