How a New Case Is Initialized in reverse‑skill: Complete PowerShell Bootstrap Guide
case-init.ps1 creates a structured work directory with validated scope, timeline, and workitems files by orchestrating master-route.ps1, enforcing the repository's authentication gate before any security testing ACT can execute.
The reverse-skill repository implements a disciplined, file-driven workflow for security research and penetration testing. Every engagement begins with formal case initialization—a mandatory step that provisions the work/<CaseName> directory structure and validates operational parameters according to RULES.md. This guide examines the initialization pipeline implemented in skills/scripts/case-init.ps1 and its dependencies.
How case-init.ps1 Bootstraps a Fresh Analysis Case
The initialization script serves as the single entry point for provisioning new engagements. It performs six sequential operations that transform a user hint into a governed workspace.
1. Resolve and Create the Working Directory
case-init.ps1 delegates path resolution to an internal helper, WorkRoot.ps1, which locates the repository-wide work folder and creates the case-specific subdirectory:
work\<CaseName>\
This directory becomes the canonical location for all case artefacts. Subsequent scripts—including case-guard.ps1 and append-evidence.ps1—depend on this predictable structure.
2. Validate the Case Name
Before any filesystem operations, case-init.ps1 applies strict validation rules to prevent path traversal and filesystem pollution. The script rejects:
- Wildcard characters (
*,?) - Trailing whitespace
- Control characters
Invalid names trigger immediate termination with an explanatory error.
3. Invoke master-route.ps1 for Primary Skill Routing
The script passes the user-supplied -Hint (a one-sentence task description) to skills/scripts/master-route.ps1. This router analyzes the hint and produces route-scope.md containing:
- A primary-skill recommendation
- A basic timeline skeleton
This file feeds directly into the case artefacts created in step 4.
4. Populate Core Case Artefacts
case-init.ps1 atomically writes three mandatory markdown files using [System.IO.File]::WriteAllText with UTF-8 encoding:
| File | Purpose | Source Contract |
|---|---|---|
scope.md |
Operational contract defining auth status, in-scope targets, network profile | skills/ops/scope-contract.md |
timeline.md |
Placeholder for engagement milestones | Derived from route-scope.md |
workitems.md |
Empty list for tracking actionable tasks | Repository template |
The script copies route-scope.md into the case folder before populating these files, ensuring the primary skill recommendation persists.
5. Apply the Authentication and Networking Gate
case-init.ps1 implements the security gate mandated by RULES.md: no ACT (action) may execute until auth.status=granted and a valid network_profile exist.
With explicit parameters:
-AuthGranted -TargetUrl "https://target.example" -NetworkProfile authorized_target_only
The script pre-fills scope.md with:
auth.status: grantedin_scope: <TargetUrl>
Without parameters:
The script leaves placeholder values and prints a mandatory reminder:
1. Edit `scope.md` — set auth.status=granted and in_scope (or re-run with -AuthGranted -TargetUrl)
NEXT: fill scope.md auth + in_scope; then open PRIMARY SKILL.md
This mirrors the enforcement logic in case-guard.ps1, which validates scope.md before permitting any ACT execution.
6. Finalize with Diagnostics
The script concludes by:
- Echoing the absolute path to
work\<CaseName> - Listing all generated artefacts
- Aborting with detailed error context if any step fails
Practical Code Examples
Basic Initialization
powershell -NoProfile -ExecutionPolicy Bypass `
-File skills/scripts/case-init.ps1 `
-Hint "web pentest of corporate portal" `
-CaseName "corp-web-2024"
This creates:
work\corp-web-2024\scope.mdwork\corp-web-2024\timeline.mdwork\corp-web-2024\workitems.md
Automated Pipeline Initialization
powershell -File skills/scripts/case-init.ps1 `
-Hint "internal API audit" `
-CaseName "api-audit-jan" `
-AuthGranted `
-TargetUrl "https://api.internal.company" `
-NetworkProfile authorized_target_only
Post-execution verification checklist:
- Open
work\api-audit-jan\scope.md - Confirm
auth.status: granted - Validate
in_scopematcheshttps://api.internal.company - Review
PRIMARY SKILL.mdfor recommended tooling
Key Source Files and Their Roles
Understanding the initialization flow requires familiarity with these repository components:
skills/scripts/case-init.ps1— Core bootstrap script; orchestrates directory creation, routing, and artefact generationskills/scripts/master-route.ps1— Generates initial skill routing and timeline data consumed bycase-init.ps1skills/ops/scope-contract.md— Specification governing validscope.mdstructure, including required fields for authentication status and network profileRULES.md— Mandatescase-initexecution before any ACT; defines the security gate enforced bycase-init.ps1andcase-guard.ps1skills/scripts/case-guard.ps1— Validates thatscope.mdexists and containsauth.status=grantedbefore permitting ACT execution
Summary
The reverse-skill initialization pipeline guarantees reproducible, governed engagement setup:
case-init.ps1is the mandatory entry point for all new cases- The script creates a structured
work/<CaseName>directory with three core artefacts:scope.md,timeline.md, andworkitems.md master-route.ps1provides skill routing recommendations based on the-Hintparameter- Authentication gating is enforced at initialization; cases without
auth.status=grantedcannot proceed to ACT execution - All file writes are atomic and UTF-8 encoded, preventing corruption during concurrent access
- The implementation follows the contract defined in
skills/ops/scope-contract.mdand the rules inRULES.md
Frequently Asked Questions
What happens if I skip case-init.ps1 and try to run an ACT directly?
case-guard.ps1 will block execution. According to RULES.md, every ACT must be preceded by a valid scope.md with auth.status=granted. The guard script checks for this file and its required fields before allowing any action to proceed.
Can I rename a case after initialization?
The repository does not provide a native rename operation. You must manually move the work/<CaseName> directory and update any internal references. Future iterations of case-init.ps1 may add -Rename functionality, but this is not currently implemented.
How does master-route.ps1 determine the primary skill?
The router parses your -Hint string against embedded heuristics and produces route-scope.md with a recommended skill category and initial timeline. This recommendation is advisory; you may override it manually in scope.md before opening PRIMARY SKILL.md.
What network profiles are valid for -NetworkProfile?
Valid values are defined in skills/ops/scope-contract.md. Common profiles include authorized_target_only, corporate_lan, and airgapped. The profile affects which network behaviors are permitted during ACT execution and is validated by case-guard.ps1.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →