CtrlK
BlogDocsLog inGet started
Tessl Logo

hunt-laravel

Hunt Laravel specific vulnerabilities — Debug mode leakage (APP_DEBUG=true exposes full stack trace + env vars), Laravel Telescope/Horizon dashboard unauthorized access, Ignition RCE (CVE-2021-3129), Signed URL manipulation, Queue Worker abuse, mass assignment via Eloquent, deserialization via cookies, .env file exposure. Use when target runs Laravel (PHP) — detected via X-Powered-By, Laravel session cookies, or /storage/ paths.

71

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, highly actionable Laravel exploitation playbook with executable commands per phase and a validation/severity section. Its main gap is the absence of explicit retry/feedback loops for destructive operations and any progressive-disclosure references.

Suggestions

Add explicit feedback loops for destructive steps (e.g. for CVE-2021-3129: 'If no output, confirm debug mode is on and storage/logs is writable, then re-run') to push workflow_clarity toward 5.

Move the per-vulnerability deep-dive payloads (e.g. phpggc gadget chains, cookie-forgery details) into a referenced reference file so SKILL.md stays an overview, improving progressive_disclosure.

Tighten the few inline impact comments in Phase 4/Phase 7 to keep conciseness at the lean 5 anchor.

DimensionReasoningScore

Conciseness

Lean, command-first prose that assumes Claude already knows Laravel/PHP and CVEs; a few inline impact comments (e.g. "→ Can decrypt all Laravel encrypted cookies") are justifiable context for a hunt skill rather than padding, leaving only minor trim opportunities.

4 / 5

Actionability

Every phase is built from copy-paste-ready curl/git/php commands with real endpoints, headers, and JSON payloads (e.g. the _ignition/execute-solution POST body), covering the common exploitation cases concretely.

5 / 5

Workflow Clarity

Phases 1–7 are clearly sequenced and a Validation section with a ✅ checklist plus severity table supplies explicit verification; it stays at 4 rather than 5 because there are no explicit error-recovery/retry feedback loops for the destructive RCE/ATO steps.

4 / 5

Progressive Disclosure

No bundle files exist, so the skill is a single well-organized SKILL.md split into clearly headed phases with a chain table; the >50-line body is appropriately sectioned but lacks the one-level-deep external references that would reach the 5 anchor.

4 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that names concrete Laravel vulnerability classes and gives explicit, detection-based 'Use when' guidance in third person. Minor synonym coverage gaps in trigger terms keep it just shy of a perfect 5 on that one dimension.

DimensionReasoningScore

Specificity

Lists eight concrete, named Laravel vulnerability classes ("Ignition RCE (CVE-2021-3129)", "Telescope dashboard", "Signed URL manipulation", ".env file exposure", "mass assignment via Eloquent", "deserialization via cookies") — comprehensive, multi-action coverage, not a level below which requires minor gaps.

5 / 5

Completeness

It explicitly answers both what ("Hunt Laravel specific vulnerabilities" plus the enumerated list) and when ("Use when target runs Laravel (PHP) — detected via X-Powered-By, Laravel session cookies, or /storage/ paths") with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural terms a user would say are well covered ("Laravel", "PHP", "Laravel session cookies", "/storage/ paths", "X-Powered-By") alongside detection hints; a few common synonyms/variations are absent, so it stops short of the 5 anchor's comprehensive synonym coverage.

4 / 5

Distinctiveness Conflict Risk

A tightly scoped Laravel-only niche with concrete detection triggers (session cookies, /storage/ paths) makes false-trigger conflict with other skills minimal — a clear distinct niche.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.