# Pwnote

> Open-source publisher. Listings imported from github.com/Pwnote — credited to the original author with their license.

- **Listings:** 8
- **Total installs:** 0
- **Profile:** https://agentstack.voostack.com/s/pwnote
- **Website:** https://github.com/Pwnote

## Published listings

- [Pwnote Offsec Osai](https://agentstack.voostack.com/l/skill-pwnote-skills-pwnote-offsec-osai) — Skill · Free · security-reviewed — `agentstack add skill-pwnote-skills-pwnote-offsec-osai`
  Use whenever the user is working on Offsec's OSAI / AI Red Teaming certification track, or on AI/LLM/agentic security engagements generally — prompt injection findings, tool-use abuse, agent trajectory documentation, or writing up AI-specific security findings that don't map cleanly to traditional CVSS. Trigger on "OSAI", "AI Red Teaming", "LLM pentest", "prompt injection engagement", or "agentic…
- [Pwnote Engagement File](https://agentstack.voostack.com/l/skill-pwnote-skills-pwnote-engagement-file) — Skill · Free · security-reviewed — `agentstack add skill-pwnote-skills-pwnote-engagement-file`
  Create or validate a pwnote engagement import/export JSON file. Use when the user wants to generate, edit, or verify a pwnote engagement file for data transfer between pwnote instances. The file bundles an entire pentest engagement — metadata, notebook documents, code/host/credential blocks, findings with CVSS/cwe/cve, attack-path boards, and activity history. Also use when the user asks how to s…
- [Pwnote Cve Research](https://agentstack.voostack.com/l/skill-pwnote-skills-pwnote-cve-research) — Skill · Free · security-reviewed — `agentstack add skill-pwnote-skills-pwnote-cve-research`
  Use whenever the user is doing vulnerability research aimed at a CVE/advisory — tracking a responsible disclosure timeline, drafting a vendor notification, requesting a CVE ID from MITRE or a CNA, writing a public security advisory, or mapping a finding to a CWE. Trigger on "CVE", "CNA", "MITRE", "advisory", "responsible disclosure", "vendor notification", "embargo", or "disclosure timeline", eve…
- [Pwnote Bug Bounty](https://agentstack.voostack.com/l/skill-pwnote-skills-pwnote-bug-bounty) — Skill · Free · security-reviewed — `agentstack add skill-pwnote-skills-pwnote-bug-bounty`
  Use whenever the user is working a bug bounty program — parsing scope/rules of engagement, planning or running recon, triaging findings, writing up a report for HackerOne/Bugcrowd/Intigriti/YesWeHack, handling program manager pushback or duplicate/N-A disputes, or asking how to structure notes for a bounty target. Trigger on mentions of "bug bounty", "program scope", "recon on [target]", "write t…
- [Pwnote Hackthebox](https://agentstack.voostack.com/l/skill-pwnote-skills-pwnote-hackthebox) — Skill · Free · security-reviewed — `agentstack add skill-pwnote-skills-pwnote-hackthebox`
  Use whenever the user is working a HackTheBox (HTB) machine or challenge — structuring recon/foothold/privesc notes, building an enumeration checklist, tracking a multi-hop attack path, or writing a writeup (respecting HTB's retirement rules before publishing). Trigger on "HTB", "HackTheBox box", "pwn this machine", or "root this box", even without the word "skill".
- [Pwnote Offsec Pen200](https://agentstack.voostack.com/l/skill-pwnote-skills-pwnote-offsec-pen200) — Skill · Free · security-reviewed — `agentstack add skill-pwnote-skills-pwnote-offsec-pen200`
  Use whenever the user is working on Offsec's PEN-200 course/OSCP — PWK lab notes, exam report drafting, screenshot/evidence discipline, or exam flag handling. Trigger on "OSCP", "PEN-200", "PWK", "OSCP exam report", or "proof.txt", even without the word "skill".
- [Pwnote Offsec Web300](https://agentstack.voostack.com/l/skill-pwnote-skills-pwnote-offsec-web300) — Skill · Free · security-reviewed — `agentstack add skill-pwnote-skills-pwnote-offsec-web300`
  Use whenever the user is working on Offsec's WEB-300 course/OSWE — whitebox source code review methodology, exploit chain documentation, PoC scripting, or OSWE exam report writing. Trigger on "OSWE", "WEB-300", "whitebox", "source code review" in a pentest context, or "exploit chain", even without the word "skill".
- [Pwnote Tryhackme](https://agentstack.voostack.com/l/skill-pwnote-skills-pwnote-tryhackme) — Skill · Free · security-reviewed — `agentstack add skill-pwnote-skills-pwnote-tryhackme`
  Use whenever the user is working through a TryHackMe (THM) room — taking structured notes per task, writing a public-facing writeup or blog post, tracking flags, or dealing with THM-specific tooling (AttackBox, OpenVPN connection issues). Trigger on "TryHackMe", "THM room", "writeup for [room name]", or "walkthrough", even without the word "skill".

---
Seller on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Install any with `agentstack add <slug>`.
