Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/encod3d-sec/torch/claude-mdgit clone --depth 1 https://github.com/Encod3d-Sec/TORCHWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/encod3d-sec/torch/claude-md)<a href="https://agentmods.dev/instructions/encod3d-sec/torch/claude-md"><img src="https://agentmods.dev/badge/instructions/encod3d-sec/torch/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.07786 | $0.07786 |
| Opus 5 | $0.03893 | $0.03893 |
| Sonnet 5 | $0.01557 | $0.01557 |
| Haiku 4.5 | $0.00779 | $0.00779 |
Grade A, and why
TORCH CLAUDE.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
(nmap/ffuf/nuclei/httpx/nxc/sqlmap/borg/...), never a hand-rolled `curl`/`/dev/tcp` loop; if none How it starts
The opening of the file, as written. The whole thing — 242 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Pentesting & Bug Bounty Wiki: Schema
Quick reference
| Operation | Action |
|---|---|
| Query | qmd_query "..." via wiki-search MCP -> read results -> synthesise |
| Ingest skip check | Read frontmatter only; skip page if ingest slug already in sources: |
| Re-index / wiki status | wiki skill |
| Git clone | Always WSL: wsl -d kali-linux -u kali -- git clone <url> /home/kali/<name> |
| Run tooling against a target | Kali VM over SSH: bash /root/vm.sh '<cmd>' (VPN route + tools + chromium live there) -> docs/virtual-machine.md |
Skills and tools
| Task | Use |
|---|---|
| Multi-step planning | superpowers:brainstorming then superpowers:writing-plans |
| Execute a plan | superpowers:subagent-driven-development |
| Debug unexpected behavior | superpowers:systematic-debugging |
| About to claim done | superpowers:verification-before-completion |
Write/edit vault .md |
obsidian:obsidian-markdown |
| Fetch URL for ingest | WebFetch tool |
| Read vault file | Read tool with machine path (see below) |
| Search vault | qmd_query (semantic) or qmd_search (keyword) via wiki-search MCP |
| Maintain wiki index (re-index, status) | wiki skill |
| Load engagement playbook / FIND schema | Read targets/TARGETS.md |
| Audit CLAUDE.md (full review) | claude-md-management:claude-md-improver |
| Update CLAUDE.md (targeted session learnings) | claude-md-management:revise-claude-md |
| Session end / pause work | gsd:pause-work (optional plugin) or the manual pause-work steps |
| Parallel independent tasks | superpowers:dispatching-parallel-agents |
| Run a full bb/pt/ctf engagement autonomously | bb-workflow / pt-workflow / ctf-workflow skill (driver: scripts/campaign.py; the single source of truth for the execution loop) |
| Check the workflow driver is set up on this machine | campaign-health skill (scripts/campaign-doctor.py) |
| About to attack a web endpoint | hunt-<type> skill (see auto-triggers below) |
| Driving a web target through Burp (proxy-history triage, Repeater/Intruder/Collaborator) | hunt-burp skill (Burp MCP; setup [[burp-mcp]]) |
| Starting recon on any target | wiki-recon skill |
| Manual login / MFA the agent can't do headlessly (Smart-ID, Mobile-ID, captcha) + drive & observe via CDP | chrome-devtools-browser skill (visible chromium on the VM via scripts/browser-visible.sh + chrome-devtools MCP) |
| Manual login / MFA the agent can't do headlessly (Smart-ID, Mobile-ID, captcha) + drive & observe via CDP | chrome-devtools-browser skill (visible chromium on the VM via scripts/browser-visible.sh + chrome-devtools MCP) |
| Validating / moving finding to Completed | triage then evidence skills |
| Vuln/CVE research on a target (binary/repo/app/firmware) | research skill (scaffolds raw/research/<project>/) |
| Hand a fiddly, fully-specified exploit-compile/escalation run to a sub-agent | delegate skill (autonomous sub-agent exploit-run; false-root/hostname guardrail mandatory) |
| Drive msfconsole (recon, exploit search/run, reverse shells, post-ex) | metasploit skill (msfconsole framework-driver; cheatsheet [[metasploit]]) |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · +1 lines · +55 tokens per session d3a28a789430
- 5d ago First seen · 241 lines · 7,731 tokens per session scan A 8b5a42e8cb89
TORCH CLAUDE.md is an instructions file published in the GitHub repository Encod3d-Sec/TORCH (284 stars, last pushed 3d ago), licensed MIT. It adds 7,786 tokens to every session, about $0.0389 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
next.js AGENTS.md
Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.