<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/demystifying-agent-tradecraft-introducing-specterops-skills-fkdmgshdy" -->

---
title: Demystifying Agent Tradecraft: Introducing SpecterOps Skills
description: SpecterOps introduces an open-source repository called SpecterOps Skills, packaging reusable AI agent skills, plugins, and agent definitions for security...
canonical: https://daily.dev/posts/demystifying-agent-tradecraft-introducing-specterops-skills-fkdmgshdy
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Demystifying Agent Tradecraft: Introducing SpecterOps Skills | daily.dev
og:description: SpecterOps introduces an open-source repository called SpecterOps Skills, packaging reusable AI agent skills, plugins, and agent definitions for security...
og:url: https://daily.dev/posts/demystifying-agent-tradecraft-introducing-specterops-skills-fkdmgshdy
og:image: https://api.daily.dev/og/posts/fkdMGsHDY.png
og:image:alt: Demystifying Agent Tradecraft: Introducing SpecterOps Skills
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Demystifying Agent Tradecraft: Introducing SpecterOps Skills

**[SpecterOps](https://daily.dev/sources/specterops)** · 6 min read · 1 upvotes · 0 comments

## Summary

SpecterOps introduces an open-source repository called SpecterOps Skills, packaging reusable AI agent skills, plugins, and agent definitions for security research and offensive tradecraft. As of August 2026, the project contains 26 plugin families, 79 skills, and 22 agent definitions covering areas like reconnaissance, application security, reverse engineering, adversary simulation, and BloodHound analysis. The material works with Codex and Claude Code plugins and can be installed via the npx skills ecosystem, with integrations for BloodHound, Ghostwriter, Binary Ninja, and Ghidra. The post outlines a maintenance model built on six principles: practitioner-led contributions, explicit lifecycle and ownership, review for utility and risk, portable multi-client design, reproducible maintenance, and transparent limitations, drawing on lessons from prior SpecterOps research on MCP and context design.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://specterops.io/blog/2026/09/02/specterops-skills>

## Questions this post answers

### What is SpecterOps Skills and what does it include?

SpecterOps Skills is an open-source repository of reusable AI agent skills, plugins, and agent definitions for security work, available on GitHub under SpecterOps/skills. As of August 2026 it contains 26 plugin families, 79 skills, and 22 agent definitions, with 23 plugins active and 3 incubating, covering areas like code review, reconnaissance, application security, reverse engineering, BloodHound analysis, and C2 extension development.

_daily.dev surfaces releases like this for practitioners standardizing AI-assisted security workflows._

### How can I use SpecterOps Skills with Claude Code or Codex?

The skills can be consumed through Codex and Claude Code plugins for full workflow integration, or individual skills can be installed via the npx skills ecosystem when the entire plugin isn't needed. External integrations like BloodHound, Ghostwriter, Binary Ninja, and Ghidra remain explicit dependencies that users configure deliberately so they can see what data crosses system boundaries.

_Developers wiring agent skills into their coding tools can track releases like this on daily.dev._

### What did SpecterOps learn from redesigning the BloodHound MCP server after a year of use?

Exposing more tools to an agent did not make it a more capable analyst; a smaller tool catalog, recoverable errors, domain-specific references, and prompts guiding the workflow performed better than teaching the entire domain at once. Matthew Nickerson summarized this finding as 'MCP design is context design,' a principle SpecterOps then applied to its broader skills repository.

_Teams designing MCP servers can follow lessons like this via daily.dev before over-engineering their tool catalogs._

---

Tags: [#security](https://daily.dev/tags/security), [#open-source](https://daily.dev/tags/open-source), [#ai-agents](https://daily.dev/tags/ai-agents), [#mcp](https://daily.dev/tags/mcp)

[View this post on daily.dev](https://daily.dev/posts/demystifying-agent-tradecraft-introducing-specterops-skills-fkdmgshdy)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Demystifying Agent Tradecraft: Introducing SpecterOps Skills","url":"https://daily.dev/posts/demystifying-agent-tradecraft-introducing-specterops-skills-fkdmgshdy","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/demystifying-agent-tradecraft-introducing-specterops-skills-fkdmgshdy"},"datePublished":"2026-09-02T18:04:35.318Z","dateModified":"2026-09-13T22:01:13.907Z","description":"SpecterOps introduces an open-source repository called SpecterOps Skills, packaging reusable AI agent skills, plugins, and agent definitions for security...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/bcdc6bece8a356f0b1293badb357a815?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/bcdc6bece8a356f0b1293badb357a815?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"SpecterOps","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"SpecterOps","logo":"https://media.daily.dev/image/upload/s--lR36Z4gn--/f_auto,q_auto/v1787487384/logos/specterops?_a=BAMAMicg0","url":"https://daily.dev/sources/specterops"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/demystifying-agent-tradecraft-introducing-specterops-skills-fkdmgshdy","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,open-source,ai-agents,mcp","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"SpecterOps","item":"https://daily.dev/sources/specterops"},{"@type":"ListItem","position":3,"name":"Demystifying Agent Tradecraft: Introducing SpecterOps Skills"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/demystifying-agent-tradecraft-introducing-specterops-skills-fkdmgshdy#faq","mainEntity":[{"@type":"Question","name":"What is SpecterOps Skills and what does it include?","acceptedAnswer":{"@type":"Answer","text":"SpecterOps Skills is an open-source repository of reusable AI agent skills, plugins, and agent definitions for security work, available on GitHub under SpecterOps/skills. As of August 2026 it contains 26 plugin families, 79 skills, and 22 agent definitions, with 23 plugins active and 3 incubating, covering areas like code review, reconnaissance, application security, reverse engineering, BloodHound analysis, and C2 extension development. daily.dev surfaces releases like this for practitioners standardizing AI-assisted security workflows."}},{"@type":"Question","name":"How can I use SpecterOps Skills with Claude Code or Codex?","acceptedAnswer":{"@type":"Answer","text":"The skills can be consumed through Codex and Claude Code plugins for full workflow integration, or individual skills can be installed via the npx skills ecosystem when the entire plugin isn't needed. External integrations like BloodHound, Ghostwriter, Binary Ninja, and Ghidra remain explicit dependencies that users configure deliberately so they can see what data crosses system boundaries. Developers wiring agent skills into their coding tools can track releases like this on daily.dev."}},{"@type":"Question","name":"What did SpecterOps learn from redesigning the BloodHound MCP server after a year of use?","acceptedAnswer":{"@type":"Answer","text":"Exposing more tools to an agent did not make it a more capable analyst; a smaller tool catalog, recoverable errors, domain-specific references, and prompts guiding the workflow performed better than teaching the entire domain at once. Matthew Nickerson summarized this finding as 'MCP design is context design,' a principle SpecterOps then applied to its broader skills repository. Teams designing MCP servers can follow lessons like this via daily.dev before over-engineering their tool catalogs."}}]}
```

