xaccefy/pi-xpi
XPI — offensive security tools for Pi Agent and OMP (fork): casefile ledger with honest-PoC gates, web lookup, exploit technique search, and todo tracking.
Use when tracking security investigations, bug bounty findings, CTF leads, audit evidence, exploit chains, dead ends, or reports in the Casefile ledger.
Bounded swarm vulnerability discovery pipeline for broad bug-bounty or security-audit sweeps. Use when the user explicitly asks for the full pipeline, enables /xp or /xp swarm, or wants parallel specialist review. Prefer /xp lite or the casefile skill for CTFs, focused one-target work, and single suspected bugs.
Web application penetration testing methodology for Pi agent — reconnaissance, auth handling, per-class attack methodology, detection, confirmation, evasion, and reporting. Use when testing a live web target within a sanctioned engagement. Per-class methodology lives in classes/<slug>.md; read only the class(es) you are assigned.