# Hunt Plan

> Create phase plans for a threat hunt with exact telemetry tasks, receipts, and query outputs

- Skill: `aibot88/hunt-plan` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add aibot88/hunt-plan`
- Raw SKILL.md: https://api.skillmd.com/api/skills/aibot88/hunt-plan/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: aibot88 (https://skillmd.com/u/aibot88)
- Updated: 2026-09-09
- Page: https://skillmd.com/skills/aibot88/hunt-plan

---


<objective>
Plan a hunt phase from the current HUNTMAP.

`HUNTMAP.md` remains the source of truth for phase layout and sequencing.

**Creates or updates:**
- `.planning/phases/[phase-slug]/`
- `CONTEXT.md`
- `PLAN.md` files
- `.planning/STATE.md`
- `.planning/HUNTMAP.md` when phase metadata changes

**After this command:** Run `/hunt-run <phase>`.
</objective>

<execution_context>
@.github/thrunt-god/workflows/hunt-plan.md
@.github/thrunt-god/templates/context.md
@.github/thrunt-god/templates/phase-prompt.md
</execution_context>

<process>
Execute the hunt planning workflow from @.github/thrunt-god/workflows/hunt-plan.md.
Plans must name the telemetry source, intended evidence, and required receipts.
</process>

