CtrlK
BlogDocsLog inGet started
Tessl Logo

hunt-aspnet

Hunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encrypted), machineKey recovery, dual-parser MAC-bypass anti-pattern, request-validator bypass, trace.axd/elmah.axd disclosure, load-balanced ViewState cross-node failures, SafeControl enumeration via reflection, customErrors mode=Off stack-trace leaks, classic Webforms .aspx/.asmx/.svc surface. Built for ASP.NET Webforms + WCF + SharePoint farms.

73

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

100%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A high-quality, actionable hunting skill: lean token-efficient prose, executable detection code, a sequenced methodology with explicit validation gates, and clean section-based organization. It exemplifies the good-overall patterns the rubric rewards.

DimensionReasoningScore

Conciseness

Dense and information-rich with no padding of concepts Claude already knows (no 'what is ASP.NET/ViewState' exposition); every section earns its place through compact code blocks, header listings, and tables. The only near-promotional line ('pay among the highest amounts in bug bounty') serves as concrete prioritization context rather than filler.

3 / 3

Actionability

Provides fully executable, copy-paste-ready curl and Python — the ViewState parser-error differential probe script, trace.axd anonymous check, WCF enumeration grep, and Telerik fingerprint — plus exact error strings, headers, and URL patterns to match on. Concrete guidance with no pseudocode gaps.

3 / 3

Workflow Clarity

A 12-step sequenced hunting methodology with explicit validation checkpoints: Step 4 classifies parser-error differentials, the 'Gate 0 Validation' section gates severity on attacker-attainable impact, and the 'reproduce in <10 min' checklist creates a feedback loop. Clear sequence with explicit validation for risky/disclosure operations.

3 / 3

Progressive Disclosure

No bundle files exist (references/scripts/assets absent); peer-skill references (hunt-sharepoint, hunt-rce, triage-validation) are one level deep and clearly signaled. The body is well-organized into distinct navigable sections (Crown Jewel Targets, Attack Surface Signals, Methodology, Payload Patterns, Root Causes, Bypass Techniques, Gate 0, Impact Examples, Related Skills) with no nested/deep references.

3 / 3

Total

12

/

12

Passed

Description

82%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A dense, specific description with strong trigger-term coverage and a clear distinct niche. Its main weakness is the absence of an explicit 'Use when...' clause, which leaves the when-to-use guidance implied rather than stated.

Suggestions

Add an explicit 'Use when ...' clause, e.g. 'Use when hunting ASP.NET Webforms/WCF/SharePoint surface or when fingerprinting reveals __VIEWSTATE, .aspx/.asmx/.svc, or X-AspNet-Version headers.'

Soften or split the most jargon-dense phrase ('dual-parser MAC-bypass anti-pattern') so a user scanning skill descriptions recognizes a natural trigger phrase.

DimensionReasoningScore

Specificity

Lists multiple concrete actions and targets — 'ViewState deserialization (signed-only vs encrypted)', 'machineKey recovery', 'request-validator bypass', 'trace.axd/elmah.axd disclosure', 'SafeControl enumeration via reflection' — matching the multiple-specific-actions anchor. Third person voice ('Hunt...') is correctly used.

3 / 3

Completeness

Clearly answers 'what' with an extensive surface list, but lacks an explicit 'Use when...' trigger clause — 'Built for ASP.NET Webforms + WCF + SharePoint farms' states scope without explicit when-to-use guidance, capping completeness at 2 per the rubric guideline.

2 / 3

Trigger Term Quality

Good coverage of natural domain terms a user would say — 'ASP.NET', 'ViewState', 'machineKey', 'trace.axd', 'elmah.axd', 'SharePoint', 'WCF', '.aspx/.asmx/.svc'. Some phrasing ('dual-parser MAC-bypass anti-pattern') is technical, but the core trigger vocabulary is well represented.

3 / 3

Distinctiveness Conflict Risk

Highly specific ASP.NET hunting niche with distinct triggers (.aspx, ViewState, machineKey, trace.axd) unlikely to overlap with unrelated skills; 'Built for ASP.NET Webforms + WCF + SharePoint farms' defines a clear, non-generic niche.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.