Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add jessefmoore/offensive-claude-code --skill hacksmarter-labsgit clone --depth 1 https://github.com/jessefmoore/offensive-claude-codeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jessefmoore/offensive-claude-code/hacksmarter-labs)<a href="https://agentmods.dev/skills/jessefmoore/offensive-claude-code/hacksmarter-labs"><img src="https://agentmods.dev/badge/skills/jessefmoore/offensive-claude-code/hacksmarter-labs.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00058 | $0.03743 |
| Opus 5 | $0.00029 | $0.01871 |
| Sonnet 5 | $0.00012 | $0.00749 |
| Haiku 4.5 | $0.00006 | $0.00374 |
Grade B, and why
hacksmarter-labs scanned grade B with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Asks for rootmediumPrivilege escalation
A mod that escalates privileges can change anything on the machine, not only the project.
echo "10.1.x.x dc01.<domain> <domain>" | sudo tee -a /etc/hosts Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
# WebFetch / curl with the ask param for a specific step How it starts
The opening of the file, as written. The whole thing — 182 lines — stays where its author put it; the contents beside it link to each section on GitHub.
HackSmarter Labs
When to Activate
- The user is on the HackSmarter VPN attacking a lab box (target in
10.1.0.0/16). - They name a 2025 lab (Welcome, Hunter, Arasaka, Odyssey, PivotSmarter, etc.).
- They ask "how do I approach this HackSmarter box" or share a lab IP/hostname.
This skill is a range-specific overlay. It tells you the conventions of the HackSmarter environment and which archetype a box is, then hands off to the deep skills:
- AD chains →
skills/active-directory-attack/SKILL.md - nxc syntax →
skills/netexec/SKILL.md - Web exploitation →
skills/web-pentest/SKILL.md - Linux privesc →
skills/privesc-linux/SKILL.md - Windows privesc →
skills/privesc-windows/SKILL.md - Cloud (AWS) →
skills/cloud-security/SKILL.md
Range Conventions
| Thing | Convention | Notes |
|---|---|---|
| VPN interface | tun0 |
All Responder/ligolo/listener binds use tun0. Confirm with ip a show tun0. |
| Your attacker IP | 10.200.x.x |
This is the address targets reach back to (reverse shells, Responder, ligolo proxy). |
| Target subnet | 10.1.0.0/16 |
Each lab gets its own /24 (e.g. 10.1.239.0/24). The box IP is given on the lab page. |
| Internal/pivot subnets | second 10.1.x.0/24, reached only via a pivot host |
Multi-host labs (PivotSmarter, ShareThePain, Odyssey, NorthBridge) hide the real target behind a jump box. |
| Ligolo route | 240.0.0.1 = the agent host's own services |
ip route add 240.0.0.1 dev ligolo exposes loopback-bound services (MSSQL/MySQL on the pivot). |
| Lab domains | custom, non-routable: WELCOME.local, hack.smarter, hsm.local, polution.hsm, *.hs |
Always add the DC/host to /etc/hosts first — Kerberos and vhost routing break without it. |
| Flags | user.txt (user desktop / /home), root.txt (C:\Users\Administrator\Desktop or /root) |
Two flags per box is the norm. |
| Initial creds | Often "phished"/provided on the lab page for a low-priv user | Easy/Medium AD boxes hand you a starting identity; the lab is the chain from there. |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 182 lines · 58 tokens per session scan B 7621d58717fc
hacksmarter-labs is a skill published in the GitHub repository jessefmoore/offensive-claude-code (2 stars, last pushed 3mo ago), licensed MIT. It adds 58 tokens to every session and 3,743 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it B with 2 findings (asks for root, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
hr-onboarding
A new-hire onboarding plan as a single page — first week schedule, buddy + manager intro, learning track, equipment checklist, and "you're set when…" outcomes. Use when the brief mentions "onboarding", "new hire", "first week plan", or "入职".
book-mirror
Take any book (EPUB/PDF), produce a personalized chapter-by-chapter analysis. Each chapter is preserved in detail (The Chapter) and mirrored back to the reader's actual life (The Mirror) using brain context. The mirror observes and resonates — a friend pointing out parallels, NOT a consultant rearranging the reader's…
miniapp
Build a tiny interactive HTML playground only when someone asks to see, play with, or step through a mechanism.
eli5
Explain research, papers, or technical ideas in plain English with minimal jargon, concrete analogies, and clear takeaways. Use when the user says "ELI5 this", asks for a simple explanation of a paper or research result, wants jargon removed, or asks what something technically dense actually means.
deck-course-module
A course or workshop slide template with persistent learning goals, teaching pages, multiple-choice self-tests, and a wrap-up.
master-yinguang
A reference-based assistant for questions about Yinguang and Pure Land Buddhism, a Buddhist tradition focused on faith, ethical living, and practice connected with rebirth in the Pure Land. It can answer in Yinguang’s historical teaching style.