new

SkillSecurity

Run: uv run python3 $CLAUDEPROJECTDIR/tools/scaffold.py $ARGUMENTS

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the new skill

About this capability

Create a new engagement workspace. Usage: /new <platform> <program> [--type web-app|api|mobile|smart-contract]

What this skill tells your AI

The instructions your AI receives, as published by h-mmer/pentest-agents in .claude/skills/new/SKILL.md and read by ahel’s review.

Create a new engagement workspace: $ARGUMENTS

Parse arguments as: [--type ] Default template: web-app

Run: uv run python3 $CLAUDE_PROJECT_DIR/tools/scaffold.py $ARGUMENTS

After creation, tell the user to: cd into the workspace, start claude, and run /sync.

Top-Tier Workspace Bar

A new workspace is not ready until it can support evidence-grade hunting.

After scaffold, verify or create:

  • scope.yaml placeholder with platform, program, in-scope and out-of-scope sections
  • policy.md placeholder for required headers, rate limits, account rules, and prohibited actions
  • recon/, findings/, evidence/, poc/, reports/drafts/, and scans/
  • brain initialized or clear instruction to run /brain init
  • next commands in order: /sync, /pipeline, /analyze, then /hunt or /autopilot

Warn if the program type needs special setup: mobile test device, API tokens, sandbox tenant, OAuth app, webhook receiver, cloud account, or smart-contract fork.

Signals

GitHub stars
908
Forks
169
Last commit
Jun 2026
Advanced
Catalog kind
skill
Gateway key
new-2
Source
github.com/h-mmer/pentest-agents