Workflow
- workflow.md — Complete workflow with commands. Read this for each step
Steps
- Get Credentials —
python3 .claude/tools/env-reader.py HTB_USER HTB_PASS HTB_TOKEN ANTHROPIC_API_KEY SLACK_BOT_TOKEN HTB_SLACK_CHANNEL_ID - Only for "Machine" kind of competition -> Verify vpn is running, otherwise download the vpn file from the platform and instruct the user on how to enable it
- Generate output dirs —
mkdir -p YYMMDD_<name>/{recon,findings,logs,artifacts,tools,reports}for each challenge. Do not seedattack-chain.mdorexperiments.mdfrom the orchestrator — those are the coordinator subagent's first action (seeskills/coordination/reference/spawning-recipes.md). - To achieve the tasks given by the user, when possible use the HTB_TOKEN, otherwise login to the platform using playwright at https://account.hackthebox.com/login and fill the login form with the HTB_USER and HTB_PASS
- If necessary, start the machines
- If necessary, check network connectivity to the machines
- Spawn coordinator subagent per target —
Agent(name="coordinator-{tag}", run_in_background=True, ...)perspawning-recipes.md. Never run the P0-P6 coordinator workflow inline in the orchestrator session — the bookkeeping discipline (attack-chain.md, experiments.md, goal_attempts counting, mandatory skeptic at experiments 5/15/25) requires the subagent boundary. Max N concurrent agents, queue-based spawning. - Post-solve Phase 3 — parent orchestrator (not coordinator) always runs
/skill-update+ Slack after each coordinator returns its PHASE3_SUMMARY (see workflow.md step 8)
References
- workflow.md — Workflow overview with credentials, VPN, setup, and coordinator spawn
- spawning-recipes.md — Coordinator agent spawn prompt templates (exploitation, flag submission, completion report, stats)
- completion-report-schema.md — Challenge completion report structure & template
- slack-notifications.md — Slack completion notification format & examples
- platform-navigation.md — Platform site navigation guide
- vpn-pool-routing.md — VPN pool isolation. Pre-flight check before spawning any machine (release_arena vs dedivip_lab vs others)
- vpn-setup.md — VPN connectivity troubleshooting
- anti-bot-bypass.md — Cloudflare/Turnstile detection evasion