Analyze Sage's Phoenix/OpenInference trace database (phoenix.db) for the Sage LangGraph multi-agent system. Inspect the latest run, per-model-call token usage, errors, tool-call frequency, and compare two traces (e.g. before/after a context/token optimization). Use when asked to read the Phoenix DB, check Sage trace…
Preserve high-value Sage contracts, handoffs, reviews, transcripts, and evidence in a private project-local history while keeping payloads, credentials, locks, fixtures, clones, and other scratch work temporary.
Repo-local post-Mythic-reset Sage chat and foothold bootstrap workflow. Use to verify the Sage chat container, create or restore Apollo/Merlin footholds, check readiness, or rediscover the live CASTELBLACK callback.
Independently attest a bounded native Mythic canary by reconstructing the run from Mythic's own records with a read-only Spectator credential, then diffing those records against the frozen conversation-case expected trace. Use after a native canary run to decide whether the kernel behaved, without trusting the…
Repo-local Sage eval-gauge / hill-climbing Phase-0 toolkit. Use when an operator, Claude Code, or Codex needs to measure Sage capability with a GROUND-TRUTHED gauge (not substring eval scores), run the Gate Experiment (does the eval track reality?), compare bare-model vs harness, get the noise floor /…
Repo-local focused Sage capability, adapter, and notification validation workflow. Use when Codex, Claude Code, or an operator needs to smoke-test one generic capability, validate a Mythic capability adapter path, reproduce a focused ADCS/DCSync/GPO/LAPS/Kerberos behavior, test the fixed-content Slack findings hook…
Rebuild a live Apollo foothold on the GOAD range as NORTH\samwell.tarly with NO operator, NO RDP client, and NO X display — a pure WinRM scheduled-task (batch-logon) launch. Use to reset the range and re-establish a foothold end to end unattended (headless agent or cron), or to launch a foothold against an…
Repo-local Sage Forge/Codex helper workflow. Use when Codex, Claude Code, or an operator needs to run Sage-specific Forge helper automation or preserve Forge operational scripts outside Plans.
Repo-local Sage GOAD/Trust Walker full lab reset and readiness workflow. Use when Codex, Claude Code, or an operator asks to reset everything, perform a full reset, archive Sage/Phoenix runtime databases, reset Docker-backed Mythic, reset or verify Ludus GOAD, wipe/check BloodHound CE, restart local Sage safely…
Download an existing Mythic payload, stage it onto a Ludus Windows host over WinRM, and launch it as the current user or a supplied run-as user. Use when Codex needs to redeploy an Apollo/Sage/Mythic payload after Mythic has already built it, recover a dead GOAD callback without resetting Mythic, or help create a…
Repo-local Sage trace, Phoenix, Mythic task-output, and run-log analysis workflow. Use when Codex, Claude Code, or an operator needs to mine historical failures, inspect Phoenix spans, backfill task IDs, audit solve steps, or diagnose ingestion/file/output behavior without creating new Plans tools.
Repo-local Sage trajectory learning workflow. Use when Codex, Claude Code, or an operator needs to inventory retained Sage/Phoenix/run-log artifacts, export normalized state-action-observation-verifier-repair transition records, label repeated blocker classes, replay repair-policy decisions, or process historical DB…