Mr Robot — Security skill for Claude Code
An ADR-driven security framework for Kali — a HackTheBox co-pilot orchestrating Hat-persona Claude agents across a shared arcade and a cross-engagement memory layer.
How to install Mr Robot
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open ry-ops/mr-robot and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Mr Robot does
An ADR-driven security framework for Kali — a HackTheBox co-pilot orchestrating Hat-persona Claude agents across a shared arcade and a cross-engagement memory layer.
Alternatives in Security
- Imcodes — The IM for agents 960 ★
- Claude Bootstrap — Opinionated project initialization with security-first guardrails, spec-driven atomic todos, LLM testing patte 536 ★
- Maestro Odyssey — Long-running iterative cycle — one entry, seven modes (debug improve planex review security defensive ui) 530 ★
README
Mr. Robot
An orchestrated, ADR-driven security framework for Kali — a HackTheBox co-pilot that runs multiple "Hat" personas concurrently to compress a weekend of boxes into hours. Named for the TV series.
The idea
Mr. Robot does not hard-code its behavior. Every operating mode is an **ADR**, and every ADR prefaces a **Hat** — a persona defined along three axes: intent, ethics, and behavior. The orchestrator points Hat _robots_ at a box; they work a shared task board (the **arcade**); a declarative **playbook** turns findings into new tasks; and the campaign adapts as it runs — spreading robots across the attack surface or ganging up on one tough target.
The differentiator isn't the tooling — Kali already has the tools. The differentiator is **judgment that compounds across boxes**, which is what the memory layer (ADR-0014) is for.
The control loop
A tick is a turn. The brain reads the arcade, decides per-robot, robots act, findings come back, the playbook unlocks new tasks. "Assist vs. gang up" is not a policy switch — it's emergent from the same `ready` / `blocker` machinery.
Architecture
Two layers.
- The arsenal (layer 1, ADR-0012) — the
mr-robotMCP server: the arcade (SQLite findings store + task board), the playbook engine, the Hat registry, and a scope guard. - The orchestrator (layer 2, ADR-0013) — "Mr. Robot": spawns Hat robots as real Claude agents, runs a heartbeat control loop, and adapts.
Related Skills
Command Engagement
Shared engagement-lead SOP for the commander agents — research, write a plan, dispatch grow-agents, synthesize
Web Pentest
An experimental Claude Code skill for orchestrating authorized web application penetration tests on Kali Linux
Cross-Pollinate Hex MCP Servers
Diff-driven audit: find real transferable changes across hex-line-mcp, hex-ssh-mcp, hex-graph-mcp. Each delta
Agent Memory Vault
Markdown-first shared memory vault for Claude Code and Codex with SQLite, Zvec, Git, closeout, and audit
AuraKit
npx @smorky85/aurakit Fullstack development skill with 37 modes (BUILD/FIX/CLEAN/DEPLOY/REVIEW + 32 extended),
Module Audit
Pre-ship module audit pipeline (rev 4). 7-stage matrix audit covering form components × 4 lenses + 10 cross-cu
Related Agents
Pentest Commander
Pentest engagement lead. Owns research, planning, multi-domain grow-agent dispatch, cross-target synthesis, an
Persona Analyst
Invoke De Bono hats and multi-perspective analysis when the user asks for a hat, persona, or tension-map view.
Lead Fullstack
Use for orchestrating multi-agent tasks, cross-cutting features that span frontend and backend, senior-level t