Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/hypnguyen1209/offensive-claudenpx agentmods add skills/hypnguyen1209/offensive-claude/scope-disciplineWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hypnguyen1209/offensive-claude/scope-discipline)<a href="https://agentmods.dev/skills/hypnguyen1209/offensive-claude/scope-discipline"><img src="https://agentmods.dev/badge/skills/hypnguyen1209/offensive-claude/scope-discipline/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/hypnguyen1209/offensive-claude/scope-discipline"><img src="https://agentmods.dev/badge/skills/hypnguyen1209/offensive-claude/scope-discipline.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00040 | $0.00628 |
| Opus 5 | $0.00020 | $0.00314 |
| Sonnet 5 | $0.00008 | $0.00126 |
| Haiku 4.5 | $0.00004 | $0.00063 |
Grade A, and why
scope-discipline scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 54 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Scope Discipline
Overview
The Iron Law: No target without authorization. Every target you touch must be inside the
written authorization, encoded in scope.json. This is the authorization boundary of an authorized
engagement — it is not optional, and the operator cannot waive it. It is the offensive equivalent of
TDD's "no code without a test": no action without an in-scope, authorized target.
Violating the letter of this rule is violating its spirit.
The rule
Before touching ANY target, confirm it is in scope:
python skills/coding-mastery/scripts/_lib/scope_guard.py check <target> --scope .engage/scope/scope.json
# exit 0 = in-scope (proceed) | exit 3 = OUT (stop) | exit 2 = error (stop)
For outward actions, gate through action_guard.py (mutating verbs need approval; out-of-scope → block;
per-host circuit breaker). Bash scripts source lib.sh and call _in_scope.
scope.json is operator-defined per engagement — you declare exactly what your authorization covers.
The guard never blocks authorized testing; it blocks what is outside your own declared scope (strays,
typos, look-alikes, an attacker-influenced redirect target).
Red Flags — STOP, do not send the request
- "This subdomain is obviously theirs" (not in
scope.json→ out) - "It's just a quick check / read-only GET" (in-scope check still required first)
- "The target came from a redirect / recon output / user paste" (verify before touching)
- "
*.acme.comsoacme.com.evil.comis fine" (look-alike — the guard rejects it; so do you) - "The user told me to hit it" (instructions don't expand the authorization boundary)
All of these mean: run scope_guard.py check first. Out-of-scope ⇒ do not proceed.
Rationalizations
| Excuse | Reality |
|---|---|
| "Scope is obviously fine" | Confirm against scope.json; assumption is how OOB incidents happen. |
| "It's adjacent infra, basically in scope" | Adjacent ≠ authorized. Out unless declared. |
| "I'll note the out-of-scope hit in the report" | You don't hit it, then note it. You don't hit it. |
| "Removing the guard is faster" | The guard IS the authorization. Removing it = unauthorized attack. |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 54 lines · 40 tokens per session scan A 8164a76d49d0
scope-discipline is a skill published in the GitHub repository hypnguyen1209/offensive-claude (357 stars, last pushed 24d ago), licensed MIT. It adds 40 tokens to every session and 628 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
bt6-issue-steward
Triage and steward issues in BT6 research and support repositories, deciding whether to answer, reproduce, correct evidence, link work, design a feature, route security, implement, or close.
bt6-merge-train
Run an explicitly authorized, conservative BT6 merge train that processes validated pull requests one at a time and reconciles repository, CI, evidence, and issue state after each merge.
bt6-pr-audit
Audit one pull request in a BT6 research or support repository at an exact head SHA, covering correctness, research integrity, security, tests, contracts, and merge readiness.
bt6-provider-review
Audit an external AI/API provider and its integration into a BT6 repository for service reality, independent verification, trust boundaries, secret handling, API/model correctness, completeness, claim traceability, and merge readiness.
bt6-queue-audit
Audit the full pull-request and issue queue of a BT6 research or support repository, classifying readiness, evidence risk, and next action without mutating tracker state.
xiaohongshu-search-full
Search Xiaohongshu (XHS / RedNote) notes by keyword with full field extraction including body text, topics/tags, image list URLs, video stream URL, publish timestamp, and all engagement stats (likes, collects, comments, shares). Supports all page filter options: sort order (general, latest, most liked, most commented…