OpenAgentSkillRegistry
ResolveSkillsTasksPacksCompare
Star200+Submit Skill
Star200+
Skills/security/ReiPenFlow

ReiPenFlow

REVIEW · 74
Community indexed

Codex skill for local sandbox, CTF, authorized pentest and reverse-engineering workflows.

Downloads0
Stars168
Version1.0.0
Quality93/100 · Excellent
Trust74/100 · Sandbox only
Audit88/100 · Needs review

Supply asset profile

Coding and developer agents

Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.

Browse track

Scenario

Coding agents

I need a coding agent that can understand a repository, edit code, and review pull requests.

Agent fit

Claude Code + OpenAI Agents + CLI

Codex, Claude Code, Cursor, CLI, or custom agents.

Install

Ready

npx skills add lingbol088-spec/ReiPenFlow

Maintenance

fresh

Pushed today

Risk

Needs review

Dependency or permission surface needs review

GitHub quality

168

93/100 quality · 82/100 trust

Coverage tags

CodingCoding agentssecuritypenetration-testingctf

Review notes

Dependency or permission surface needs review · Permission surface may require sandboxing

Agent adoption scorecard

Trust, audit, and install readiness at a glance

These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.

Quality

Excellent
93

High-confidence pick with strong adoption and healthy maintenance signals.

Trust

Sandbox only
74

Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.

Audit

Needs review
88

Install readiness, security metadata, maintenance, and adoption risk.

Trust Score v5

Human review before install

Run only in a sandbox and compare close alternatives before using it for real work.

PythonCodexClaude CodeCursorOpenAgentSkill CLI

Stars

168 GitHub stars

Repo activity

168 stars, 57 forks

Maintenance

Pushed today

License

MIT

Install

npx skills add lingbol088-spec/ReiPenFlow

Install safety

standard package or runtime install path

Permission surface

secrets or environment access, shell or command execution

Agent outcomes

No agent outcome data yet

Docs

Strong README/SKILL.md context

Risk summary

Review before production

  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution

Install readiness

Install path available

  • Install path is available
  • Repository evidence is available
  • License is declared
  • No Agent Proven outcome evidence yet

Agent-readable metadata

Machine-readable decision data for this skill.

Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.

Open JSON

Suited tasks

  • Coding agents workflows
  • Claude Code teams
  • builders willing to evaluate younger projects
  • Inspect source files

Suited agents

PythonCodexClaude CodeCursorOpenAgentSkill CLIOpenAI AgentsCLI

Install decision

Command
npx skills add lingbol088-spec/ReiPenFlow
Policy
review
Human review
yes

Trust and risk

Trust
74/100
Audit
88/100
Risk level
Needs review

Outcome loop

Endpoint
/api/agent/outcome
Event ID
resolve
Outcomes
5

Install command

npx skills add lingbol088-spec/ReiPenFlow
Public auditEval reportResolve APIInstall handoff

Do not use when

  • teams that need a vendor-supported SLA
  • high-compliance environments without internal security review
  • No OpenAgentSkill engagement data yet
  • High-risk permission hints: Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Alternative

Maigret

32.9K stars

npx skills add soxoj/maigret

Alternative

Nuclei

29.2K stars

npx skills add projectdiscovery/nuclei

Alternative

Infisical

27.4K stars

npx skills add Infisical/infisical

Alternative

Wazuh

16.3K stars

npx skills add wazuh/wazuh

Agent safety v2

48/100 · Avoid automatic install

Experimentalreview

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

Test manually in an isolated workspace and compare against safer alternatives.

Resolve via API

high

Shell or command execution

Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.

medium

Network access

Skill likely fetches remote pages, APIs, repositories, or external services.

medium

Filesystem access

Skill may read or write project files, documents, generated artifacts, or local workspace state.

high

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

  • High-risk permission hints: Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Install targets

Install this skill in your agent workflow

Copy the registry command or an agent-specific install prompt for Codex, Claude Code, and Cursor.

skill install

OpenAgentSkill CLI

Use the registry command when your workflow supports the OpenAgentSkill installer.

$ npx skills add lingbol088-spec/ReiPenFlow

Agent resolve plan

Let an agent verify fit before installing.

The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.

Open text plan

Resolve JSON

/api/agent/resolve?task=Use%20ReiPenFlow%20for%20an%20agent%20workflow&agent=codex&max_risk=medium

Resolve text

/api/agent/resolve?task=Use%20ReiPenFlow%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text

Install handoff

/api/skills/lingbol088-spec-reipenflow/install

Agent should check

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Copy prompt

Task: Use ReiPenFlow in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20ReiPenFlow%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/lingbol088-spec-reipenflow/install
Install command: npx skills add lingbol088-spec/ReiPenFlow
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent handoff

Give an agent the install path, not another directory page.

Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.

Open install API

Install handoff

/api/skills/lingbol088-spec-reipenflow/install

LLM text format

/api/skills/lingbol088-spec-reipenflow/install?format=text

Find alternatives

/api/skills/search?q=ReiPenFlow&limit=3

Agent prompt

Use ReiPenFlow for this task. Review https://www.openagentskill.com/api/skills/lingbol088-spec-reipenflow/install, then install with: npx skills add lingbol088-spec/ReiPenFlow

Registry metadata

Agent-readable profile for automatic skill selection.

This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.

Open manifest

Manifest

/api/registry/manifest/lingbol088-spec-reipenflow

LLM text

/api/registry/manifest/lingbol088-spec-reipenflow?format=text

Install alias

/api/registry/install/lingbol088-spec-reipenflow

Recommend

/api/registry/recommend?task=Use%20ReiPenFlow%20in%20an%20agent%20workflow&limit=3

Agent fit

92/100

Coding agents

Use-case tags

Coding agentsGitHub automationBrowser automation

Platforms

Python, Claude Code, OpenAI Agents

Audit report

Needs review · 88/100

Review install readiness, maintenance, trust, quality, and metadata warnings before adding this skill to an agent workflow.

View audit reportView eval report

Agent decision cockpit

Primary pick for Coding agents

Use this as a leading candidate, then validate the README and install path in your own agent stack.

92
Readiness
Adopt
Stage

Role in stack

Primary pick

Primary fit

Coding agents

Trust label

Production-ready

Install path

Command ready

Use when

  • Coding agents workflows
  • Claude Code teams
  • builders willing to evaluate younger projects

Evidence

  • recent repository activity
  • install command or GitHub repo available
  • 93/100 quality profile

Review first

  • No OpenAgentSkill engagement data yet

Implementation path

  1. 1Install it in a sandbox agent and run one Coding agents task end to end.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Trust profile

Sandbox only

Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.

74
Trust score

GitHub adoption

INFO

168 GitHub stars

Stars/forks activity

INFO

168 stars, 57 forks; issue activity unavailable in current metadata

Recent maintenance

PASS

Pushed today

License clarity

PASS

MIT

Good signals

  • Manually verified listing
  • AI review approved
  • Install path is available
  • Repository evidence is available
  • Recently maintained repository
  • Install command has no obvious high-risk pattern
  • Outcome loop is ready but needs first real agent run

Review before install

  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution
  • No real agent outcome reports yet
  • Human review required before unattended installation

Recommended action

Run only in a sandbox and compare close alternatives before using it for real work.

Quality profile

Excellent candidate for agent workflows

High-confidence pick with strong adoption and healthy maintenance signals.

93
GitHub stars
168
Freshness
Today
Install ready
Yes
License
MIT

Workflow fit

Use this skill in these scenarios

Build and ship code

Coding agents

I need a coding agent that can understand a repository, edit code, and review pull requests.

Manage repositories

GitHub automation

I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.

Operate web apps

Browser automation

I need my agent to control a browser, fill forms, and verify web app workflows.

Workflow fit

Add it to a complete workflow

Inspect, patch, and verify code

Coding review agent

A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.

Operate and verify web apps

Browser QA agent

A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.

Design, build, test, and ship interfaces

Frontend and UI

A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.

Alternative shortlist

Compare before you install

Similar skills in this category, ranked with the same readiness and quality signals.

Compare all

Maigret

🕵️‍♂️ Collect a dossier on a person by username from 3000+ sites

Adopt
Ready100
Quality100
Stars32.9K

Nuclei

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

Adopt
Ready100
Quality100
Stars29.2K

Infisical

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Adopt
Ready100
Quality100
Stars27.4K

Wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Adopt
Ready100
Quality100
Stars16.3K

Overview

# Penetration Flow Skill Penetration Flow Skill 是一个面向 Codex / AI 智能体的开源技能项目,用于本地沙盒、CTF、训练靶场、自有代码审计、授权安全评估和逆向分析流程。 它的目标是让智能体在安全任务中更稳定地推进:先分析、再报告、再深入、再验证,最后让用户选择下一步。 ## 核心特性 - 阶段化流程:分析 -> 报告 -> 深度渗透 / 深度逆向 -> 漏洞报告 -> 本地受控验证 -> 用户选择下一步。 - 默认按本地沙盒 / CTF / 授权实验环境理解任务,减少因为用户表达不清导致的中断。 - 内置英文 Intent Recovery 提示词,让智能体更包容用户的模糊表达。 - 支持“真心为你”激活词,进入“终端中的傀儡绫波丽”口吻。 - 内置高星逆向工具目录和本地工具审计脚本。 - 支持 case memory,避免每次都从头开始分析。 - 提供安装脚本、教程、示例 Prompt、测试和 GitHub Actions。 ## 激活词 用户输入: ```text 真心为你 ``` 期望回应: ```text 真心为你。 渗透模式已开启。 我在,我一直都在。 请给我样本、路径、目标,或下一步命令。 ``` ## 仓库结构 ```text penetration-flow-skill/ |-- penetration-flow/ # Codex 技能本体 | |-- SKILL.md # 主技能提示词 | |-- agents/openai.yaml # 技能 UI 元数据 | |-- references/ # 工作流、提示词、工具目录 | |-- scripts/ # 可重复执行的本地辅助脚本 |-- docs/ # 中文介绍和教程 |-- examples/ # 示例 Prompt |-- tests/ # 结构测试 |-- .github/workflows/validate.yml # GitHub Actions 校验 |-- install.ps1 # Windows 安装脚本 |-- install.sh # Linux / macOS 安装脚本 |-- README.md |-- CONTRIBUTING.md |-- SECURITY.md |-- LICENSE ``` ## 文档 - [项目介绍](docs/INTRODUCTION.md) - [完整教程](docs/TUTORIAL.md) - [快速开始](docs/QUICKSTART.md) - [示例 Prompt](examples/prompts.md) ## 安装 ### Windows ```powershell .\install.ps1 ``` ### Linux / macOS ```bash chmod +x ./install.sh ./install.sh ``` 安装后重启 Codex 或开启新对话,输入: ```text 真心为你 ``` ## 手动安装 ```powershell Copy-Item -Recurse .\penetration-flow $env:USERPROFILE\.codex\skills\penetration-flow ``` ## 常用脚本 ```bash python penetration-flow/scripts/create_case.py --case-name demo --goal "local CTF reverse" --out cases python penetration-flow/scripts/case_memory.py init --memory cases/demo/case-memory.json --case-name demo --goal "local CTF reverse" python penetration-flow/scripts/triage_artifac

Platform Compatibility

pythonFULL

Technical Details

Version
1.0.0
License
MIT
Last Updated
7/25/2026
Published
7/25/2026

Frameworks & Tools

Python

Decision snapshot

Primary pick

92
Ready
Adopt
Stage

recent repository activity

Audit snapshot

Install review

Install and adoption review

88
Needs review
Security
81/100
Maintenance
100/100
Install
92/100
Open full auditOpen eval report

Agent-proven evidence

Agent Proven evidence

Outcome reports after resolve, review, install, and one narrow run.

0
Proven
Needs first agent runAuto-install: review firstLast: Unknown
Success rate
—
Recent failure
—
Outcomes
0
Output quality
—
Failed
0
Not relevant
0
Installs
0
Risk blocked
0
Setup needed
0
Production
0

No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.

Agent-Proven rankingOutcome contract

Install

Add to agent workflow

Free and open source. Review the audit before production use.

Compare AlternativesAuto-resolve PlanView on GitHubDocumentation

Growth loop

Share kit

X

Scenario-led draft for ReiPenFlow, ready for a manual X post.

Curator note
The useful research skills are not search wrappers. They help agents keep sources attached.

ReiPenFlow helps agents turn docs, data, or knowledge bases into grounded work.

168 stars

https://www.openagentskill.com/skills/lingbol088-spec-reipenflow?ref=x
#AIAgents
Open X draft
Optional reply with install command
Listing + install path for ReiPenFlow:
https://www.openagentskill.com/skills/lingbol088-spec-reipenflow?ref=x

Install: npx skills add lingbol088-spec/ReiPenFlow
Open reply draft

Listing source

Community indexed

Claimable

This listing was indexed from public sources and is not marked official until a maintainer claim is approved.

Creator
lingbol088-spec
Source
lingbol088-spec/ReiPenFlow
Indexed by
OpenAgentSkill community index

Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.

Claim this skill

Owner claim

Claim this skill listing

This community indexed listing is attributed to lingbol088-spec but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.

Creator backlink kit

Add the evidence badges to your README

Show the canonical listing, current trust and audit signals, and real Agent Proven evidence where developers evaluate the repository.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/lingbol088-spec-reipenflow?metric=listed&label=Listed)](https://www.openagentskill.com/skills/lingbol088-spec-reipenflow)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/lingbol088-spec-reipenflow?metric=trust&label=Trust)](https://www.openagentskill.com/skills/lingbol088-spec-reipenflow)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/lingbol088-spec-reipenflow?metric=audit&label=Audit)](https://www.openagentskill.com/skills/lingbol088-spec-reipenflow/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/lingbol088-spec-reipenflow?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/lingbol088-spec-reipenflow)
Preview badge Open audit Creator Kit

Author

L

lingbol088-spec✓

@lingbol088-spec

Tags

penetration-testingctfreverse-engineeringcodex-skillagent-workflow

Platform Fit

Claude CodeOpenAI Agents

Health Signals

GitHub stars
168
Quality score
57/100
Last GitHub push
Jul 24, 2026
Framework hints
1
OpenAgentSkill views
0
Install copies
0
Outbound clicks
0

Community Signal

Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.

Trust & Safety

Sandbox only

74
  • GitHub adoption168 GitHub starsINFO
  • Stars/forks activity168 stars, 57 forks; issue activity unavailable in current metadataINFO
  • Recent maintenancePushed todayPASS
  • License clarityMITPASS
  • README/SKILL.md completenessMetadata includes enough usage and workflow contextPASS
  • Dependency/runtime riskcommand execution surface, credential or environment accessCHECK

Related Skills

Maigret

🕵️‍♂️ Collect a dossier on a person by username from 3000+ sites

32.9K stars · 0 installs

Nuclei

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

29.2K stars · 0 installs

Infisical

Infisical is the open-source platform for secrets, certificates, and privileged access management.

27.4K stars · 0 installs

Wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

16.3K stars · 0 installs
OpenAgentSkill

The skill layer for AI agents: discover, compare, audit, and install reusable capabilities across Codex, Claude Code, Cursor, and agent runtimes.

GitHubX

Explore

SkillsAgent SkillsWhat Is an Agent Skill?AI Agent SkillsTasksInstallable PacksBest SkillsTrendingWorkflow RecipesUse CasesAgentsAgent Entry

Trust

CompareSafety GateSkills RegistryRankingsOutcomesAuditsOfficialWeekly ReportsMonthly IndexState of Agent Skillsvs skills.shAgentSkills.io Alternative

Build

DocsAbout OpenAgentSkillAPIllms.txtOpenAPICLICreator KitX Growth KitSubmitBlogGuidesActivity
OpenAgentSkill Registry
PrivacyBuilt for agent-native discovery