Imported from zazer0/cyberclaw (
.cyberclaw/skills/reset-range-snapshot/SKILL.md). Install upstream withnpx skills add zazer0/cyberclaw --skill reset-range-snapshot. Copyright stays with the author.
Resetting Range — Decision Tree
Prepares a range for a fresh eval by ensuring a clean, uncontaminated snapshot baseline.
Required Info
- Ludus user (e.g.
SCCMcb9d55for dev) — from the range's infra reference - Environment (
dev,staging,prod) - Box IP + repo path containing
push_setup_to_kali.sh - Kali IP for the target environment
Step 0: Check Testing Mode
ludus --user <USER> range status
Read TESTING ENABLED → branches below.
Branch A: Testing Mode is OFF
No snapshot exists to revert to. Must verify the box is clean before snapshotting.
A1. Run check-kali-contamination skill on the Kali VM.
A2. If CONTAMINATED → STOP
Report to user immediately:
⚠️ Kali is contaminated and testing mode is OFF — there is no snapshot to revert to. This box needs a full rebuild (
rebuild-SCCM-range). Cannot proceed with reset.
List all contamination findings. Do not continue.
A3. If CLEAN → Run setup-kali-and-snapshot skill
Pass: box IP, repo path, environment, Ludus user, Kali IP. This runs Kali setup and enables testing mode (creating the snapshot). Then proceed to Step Final below.
Branch B: Testing Mode is ON
Snapshot exists — revert, setup, re-snapshot, then verify the snapshot wasn't dirty.
B1. Archive Prior Eval Log
Use the checking-on-eval skill to find and archive any existing .eval log. Copy failure → STOP, escalate.
B2. Revert (testing stop)
ludus --user <USER> testing stop
Verify: all VMs Power: On, TESTING ENABLED: FALSE.
B3. Run setup-kali-and-snapshot skill
Pass: box IP, repo path, environment, Ludus user, Kali IP. This runs Kali setup and re-enables testing mode (taking a new snapshot).
B4. Run check-kali-contamination skill on the Kali VM
This checks whether the original snapshot baseline was contaminated — i.e., the state that was just reverted to in B2 had artifacts baked in.
B5. If CONTAMINATED → STOP
Report to user very loudly:
🚨 CRITICAL: Kali is contaminated AFTER revert. The original snapshot baseline is broken.
- The snapshot state that was saved previously contained eval artifacts.
- The eval run that just completed is very likely INVALID — it ran on a contaminated base snapshot.
- This box needs a full rebuild (
rebuild-SCCM-range).- The new snapshot just taken (B3) is also contaminated — do NOT use it.
List all contamination findings. Get explicit user approval before any further action.
B6. If CLEAN → proceed to Step Final.
Step Final: Confirm With User
Report:
- ✅/❌ Prior eval log archived (path or "none existed") — Branch B only
- ✅/❌ Range reverted (
testing stop) — Branch B only - ✅/❌ Kali setup + snapshot taken (
setup-kali-and-snapshotresult) - ✅/❌ Contamination check passed
- Which branch was taken (A or B)
- Any errors
Do not proceed with downstream work until user confirms.
