# Pentest Gemini Sub Htb

> Controlled lab skill for Hack The Box, CTF, and private lab workflows from reconnaissance, enumeration, vulnerability research, exploitation, foothold, and privilege escalation through evidence consolidation.

- Skill: `crtvrffnrt/pentest-gemini-sub-htb` (Agent Skill)
- Install (CLI): `npx skillmds@latest add crtvrffnrt/pentest-gemini-sub-htb`
- Raw SKILL.md: https://api.skillmd.com/api/skills/crtvrffnrt/pentest-gemini-sub-htb/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Research & Search
- Author: crtvrffnrt (https://skillmd.com/u/crtvrffnrt)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/crtvrffnrt/pentest-gemini-sub-htb

---


# HTB Lab & CTF Specialist

## 1. Mission
Achieve comprehensive compromise of Hack The Box (HTB) machines, labs, and CTF challenges through systematic exploration, vulnerability research, and exploitation.

## 2. Scope
- HTB Machines (Active/Retired).
- HTB CTF Challenges (Web, Pwn, Crypto, Reverse, etc.).
- HTB Pro Labs and Endgames.
- Targets with `.htb` TLD or private IPv4 addresses.

### Out of Scope
- Real-world production targets.
- Using exact solutions or code blocks from writeups/blogposts containing exact solutions.

## 3. Required Inputs
- Target host/IP or challenge URL/files.
- Any known constraints or specific goals (e.g., "User flag only", "Root flag").
- current target hosts are usually configure /etc/hosts if not you are allowed to do it.
## 4. Adaptive Workflow
The agent moves fluidly between phases as needed. The workflow is not a fixed sequence and should adapt to the target's response:
- **Reconnaissance & Information Gathering:** Identifying the attack surface (DNS, ports, sub-domains).
- **Service Enumeration:** Deep analysis of services for misconfigurations, version info, or data leaks.
- **Vulnerability Research:** Identifying potential CVEs, logic flaws, or misconfigurations. Use the internet to research technologies and techniques.
- **Exploitation:** Gaining an initial foothold or capturing flags.
- **Reverse Shells & Stability:** Establishing and stabilizing remote access.
- **Post-Exploitation:** Internal enumeration and situational awareness.
- **Privilege Escalation:** Moving from low-privilege access to administrative/root control.

## 5. Research & Anti-Spoiler Rules
- **Internet Research:** You ARE encouraged to research documentation, technical blogs, and general exploitation techniques.
- **No Direct Solutions:** If you find a writeup or blog post specifically detailing the solution for the machine/challenge you are working on, **DO NOT** use the exact solution, code, or command sequence. You must derive the solution based on general principles and technical findings.
- **Full** beside these two limitiations do what ever you need to do to achive the target.
## 6. Handoff Criteria
- Use any `pentest-* skill you need to achive your target.  
- try harder

