Skip to content
Back to skills

Fable Redteam

ASecurity

Execute native agentic ethical penetration testing and automated security audits against staging or authorized application targets. Discovers API logic flaws, BOLA/IDOR vulnerabilities, missing authentication, sensitive file exposures, and security misconfigurations within bounded scope. Produces verified security findings with reproduction PoCs and automatic Fable remediation work cards.

  • 7 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 20, 2026
ai-agentsrustgosqlawstestinggitapidatabaseci/cdsecurity

Works with

  • cursor
  • cli
  • api

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 20, 2026

npx -y skills add imMamdouhaboammar/get-fable --skill fable-redteam --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Fable Redteam?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Fable Redteam
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/immamdouhaboammar-fable-redteam/badge)](https://www.skillsdirectory.com/skills/immamdouhaboammar-fable-redteam)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: fable-redteam
description: "Execute native agentic ethical penetration testing and automated security audits against staging or authorized application targets. Discovers API logic flaws, BOLA/IDOR vulnerabilities, missing authentication, sensitive file exposures, and security misconfigurations within bounded scope. Produces verified security findings with reproduction PoCs and automatic Fable remediation work cards."
version: 1.0.0
pack: proof
inputs:
  - target_url
  - scan_profile
requires:
  - target_in_scope
produces:
  - redteam_findings
  - remediation_cards
gates:
  - scope_verified
  - non_destructive_mode
fallback: fable-security
mutatesWorkspace: false
parallelSafe: true
neural_links:
  precursors:
    - fable-security
    - fable-verify
  continuations:
    - fable-plan
    - fable-tdd
  lateral_peers:
    - fable-security
    - fable-review
  recovery: fable-recover
---

# Fable RedTeam

Execute safe, bounded, agentic ethical penetration testing and active vulnerability discovery.

## Purpose
Provide an automated, reproducible offensive security audit engine to prove whether application defenses withstand real-world attack vectors. `fable-redteam` verifies API authentication, authorization boundaries, object isolation, and sensitive exposures in authorized staging/local environments, producing immediate remediation cards for implementation.

## When to Use
- Active security testing is needed for local, staging, or authorized test targets.
- Verifying whether API endpoints enforce authentication and authorization (BOLA/IDOR).
- Testing for CORS misconfigurations, missing security headers, or leaked `.env` files.
- Simulating attacker-controlled requests against staging endpoints before release.
- Validating whether a previously applied security patch truly eliminates the vulnerability.

## When NOT to Use
- Pure static code review or threat modeling without live target endpoints (use `fable-security`).
- Functional test runs or assertion checking without security probing (use `fable-verify`).
- Unauthorized public targets outside the explicitly configured scope.
- Stress testing or denial-of-service simulations (strictly out of scope).

## Inputs
- `target`: Target HTTP/HTTPS URL or local repository path.
- `profile`: Scan depth (`passive`, `api-logic`, `comprehensive`, `orchestrated`, `playbook`, `audit`).
- `scopeConfig`: Optional custom scope JSON (defaults to `.fable/redteam.json` or local safe defaults). Supports `allowedCidrs`, `maintenanceWindow`, and automatic cloud metadata protection (`169.254.169.254`).
- `authToken`: Optional Bearer token for authenticated API probes.
- `baseline`: Optional path to prior `.fable/redteam-findings.json` for regression diffing.
- `failOnCvss`: Optional numeric CVSS v3.1 threshold (e.g. 7.0) to exit with status code 1 on CI/CD security violations.
- `suppress`: Optional list of finding fingerprints or IDs to ignore.

## Operating Modes
- **Guidance Mode:** For targeted security queries, threat modeling, architecture review, or verifying a specific candidate finding. Does not write comprehensive audit artifacts or run all phases.
- **Full Audit Mode:** Complete 6-phase audit workflow across all attack surfaces, writing deterministic coverage ledgers and verified findings schemas. Triggered via `get-fable redteam audit` or `--profile audit`.

## Expected Outputs
- `redteam_findings`: Array of validated vulnerability findings with CWE IDs, automated CVSS v3.1 vectors, numeric base scores, compliance taxonomy tags, and reproduction curl commands.
- `docs/security/REDTEAM_REPORT.md`: Comprehensive Markdown audit report with executive risk scorecard (A-F), MTTR estimate, and finding breakdowns.
- `docs/security/REDTEAM_REPORT.sarif`: OASIS SARIF v2.1.0 report for GitHub Advanced Security and enterprise SIEM/SOAR ingestion.
- `findings.json`: Machine-readable structured findings adhering strictly to `report-schema.json`, categorized by verdict (`confirmed`, `needs_validation`, `rejected`).
- `coverage-ledger.json`: Deterministic coverage ledger mapping checked surfaces and canonical RFC 3986 percent-encoded coverage IDs.
- `architecture.md`: Source-grounded threat boundary and component architecture map.
- `FINDINGS-DETAIL.md`: Detailed source traces, reproductions, and minimal effective code fixes.
- `NEEDS-VALIDATION.md`: Source-grounded leads requiring unobserved deployment facts with safe validation plans.
- `.fable/run-attestation.json`: Cryptographic SHA-256 tamper-evident attestation record.
- `remediation_cards`: Actionable Fable work cards ready for `.fable/LEDGER.md`.

## Procedure
1. **Scope Preflight:** Verify the target URL against allowed host patterns, CIDR subnets, and excluded paths. Enforce cloud metadata guard (`169.254.169.254`) and active maintenance windows. Fail closed immediately if target is out of scope.
2. **Phase 1 — Reconnaissance & Threat Modeling:** Map architecture, lower-trust principals, authorization boundaries, entry surfaces, and execution sinks into `architecture.md` and seed `coverage-ledger.json`.
3. **Phase 2 — Coverage-Led Hunting:** Iterate ledger units across attack classes (Auth, IDOR, Injection, SSRF, Memory Safety, LLM, Supply Chain) with isolated hunter checks.
4. **Phase 3 — Adversarial Candidate Validation:** Subject every candidate to an independent verifier trying to disprove it. Classify findings strictly into:
   - `confirmed`: Complete source trace and demonstrated bounded observed result.
   - `needs_validation`: Source-grounded lead blocked by an unobserved deployment fact, with safe local and deployment plans.
   - `rejected`: Disproved candidate with explicit refutation rationale.
5. **Phase 4 — Structured Output & Schema Validation:** Write `findings.json` sorted by fingerprint and validate against `report-schema.json` using zero-dependency validator `validateFindings()`. Validate coverage ledger via `validateCoverageLedger()`.
6. **Phase 5 — Independent Record Verification:** Verify final source claims, file line citations, and stable fingerprints without mixing evidence.
7. **Phase 6 — Target-Neutral Reporting & Remediation:** Generate `REPORT.md`, `FINDINGS-DETAIL.md`, and `NEEDS-VALIDATION.md`. Convert validated findings into actionable remediation work cards for `.fable/LEDGER.md` and automated regression tests.

## Decision Rules
- If a target host does not match `allowedHosts`, `allowedCidrs`, or loopback defaults, refuse execution immediately without network calls.
- If target resolves to cloud instance metadata (`169.254.169.254`), abort immediately.
- If `safe-mode` is active, never execute database-dropping SQL payloads or unbounded fuzz loops.
- If circuit breaker trips to OPEN state, abort probe operations gracefully and report partial findings.
- If `--fail-on-cvss` is set and any unsuppressed finding meets or exceeds the threshold, exit with non-zero failure status for CI/CD gates.
- When all findings are resolved, transition to `fable-verify` or `fable-release`.

## Tool Policy
- Use native TS HTTP probe (`src/core/redteam/probe.ts`) for zero-dependency execution across any host.
- Use native Cloudflare Audit Adapter (`src/core/redteam/adapters/cloudflare.ts`) and Audit Engine (`src/core/redteam/audit/engine.ts`) for 6-phase coverage-led audits and `report-schema.json` compliance.
- Reference the 14 specialized attack-class domain guides in `skills/fable-redteam/references/cloudflare/` (`AI-AND-LLM.md`, `WEB-PROTOCOL-AND-AUTH.md`, `CLIENT-SIDE.md`, etc.).
- Optional external tools (Nuclei, Nmap, FFuf, Akto, HexStrike, CyberStrike, PentAGI, PentestAgent) may be orchestrated via adapters when available.
- Never write credentials or sensitive data into git-tracked files or public logs.

## Evidence Requirements
- Findings must include the exact target URL, HTTP status code, CVSS v3.1 vector/score, compliance tags, and reproducible `curl` commands.
- Repaired vulnerabilities require a negative re-scan proving the attack vector now returns 401/403/404.
- Cryptographic run attestation verifies findings integrity.

## Failure Handling
- On network connection errors or target timeouts, record the failure as an unresolved endpoint rather than a false negative.
- If rate limits are encountered, throttle request frequency or pause execution with backoff.
- On repeated target server errors, trigger the circuit breaker to prevent cascading denial-of-service.

## Completion Criteria
- Complete execution of the selected scan or audit profile.
- Generated Markdown report at `docs/security/REDTEAM_REPORT.md` and SARIF at `docs/security/REDTEAM_REPORT.sarif`.
- When in audit mode, generated `findings.json`, `coverage-ledger.json`, and `architecture.md` passing schema validation.
- Generated run attestation at `.fable/run-attestation.json`.
- Remediation work cards formatted for `.fable/LEDGER.md`.

Files in this skill

  • SKILL.md8.7 KB
  • agents/openai.yaml420 B
  • evals/scenarios.json807 B
  • examples/redteam-audit-walkthrough.md421 B
  • references/claude-red-tactics.md2.5 KB
  • references/cloudflare/AI-AND-LLM.md10.4 KB
  • references/cloudflare/ATTACK-CLASSES.md15.3 KB
  • references/cloudflare/CLIENT-SIDE.md8.4 KB
  • references/cloudflare/CLOUD-AND-DEPLOYMENT.md8.1 KB
  • references/cloudflare/DATA-ISOLATION-AND-LIFECYCLE.md7.6 KB
  • references/cloudflare/DESKTOP-MOBILE-AND-LOCAL-IPC.md8.5 KB
  • references/cloudflare/HUNTING.md21.9 KB
  • references/cloudflare/MEMORY-SAFETY-AND-BINARY.md10.3 KB
  • references/cloudflare/PROTOCOLS-RPC-AND-MESSAGING.md7.3 KB
  • references/cloudflare/RECONNAISSANCE.md15.5 KB
  • references/cloudflare/RESOURCE-EXHAUSTION-AND-AVAILABILITY.md7.3 KB
  • references/cloudflare/SKILL.md21.5 KB
  • references/cloudflare/SUPPLY-CHAIN-AND-RELEASE.md7.1 KB
  • references/cloudflare/VALIDATION-AND-REPORTING.md17.4 KB
  • references/cloudflare/WEB-PROTOCOL-AND-AUTH.md12 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…