CtrlK
BlogDocsLog inGet started
Tessl Logo

hunt-misc

Hunting skill for misc vulnerabilities. Built from 225 public bug bounty reports. Use when hunting misc on any target.

54

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/hunt-misc/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a dense, highly actionable hunting playbook with executable payloads, a sequenced methodology, and strong validation gates that directly address the misc-bug N/A risk. Its only real weakness is conciseness in the narrative sections and an opportunity to externalize the payload and chain libraries into reference files.

DimensionReasoningScore

Conciseness

The body assumes Claude's competence — no padding about what SAML/Ruby/PDF libraries are — and earns most of its tokens with concrete signal, though narrative sections (Real Impact Examples, root-cause #11, the Chains) could be tightened, keeping it just below lean.

4 / 5

Actionability

Copy-paste-ready curl commands, ruby one-liners, grep patterns, and dig examples cover the common misc cases concretely and executably, with specific endpoint shapes and header values rather than pseudocode.

5 / 5

Workflow Clarity

A clearly sequenced 12-step methodology is reinforced with explicit validation checkpoints (Marker Discipline, Body-Diff Rule, Gate 0's three questions with 'must be concrete' gates and reproducibility requirements), providing feedback loops for a high-N/A-risk hunting context.

5 / 5

Progressive Disclosure

The single SKILL.md is well-organized with clear headers and signaled cross-skill references, but no bundle files exist and the large inline payload/chain sections could be split into separate reference files, leaving minor organization gaps.

4 / 5

Total

18

/

20

Passed

Description

33%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has an explicit trigger clause and cites a concrete corpus, but is vague about specific actions and uses a broad "misc" bucket that creates high overlap with sibling hunting skills. It clears the minimal bar but misses the specificity and trigger-term coverage of strong examples.

Suggestions

Enumerate 2-3 concrete actions in the description (e.g., 'Probes role/permission boundaries, invitation and token-scope flows, SAML SSO logic') to lift specificity from 2 toward 4.

Replace the generic "hunting misc" trigger with natural user phrases such as 'Use when testing access control, invitation flows, SAML SSO, or token-scope enforcement on a target'.

Narrow the scope or add a distinguishing qualifier so the description does not collide with hunt-auth-bypass, hunt-ato, and hunt-saml at trigger time.

DimensionReasoningScore

Specificity

The description names the domain ("misc vulnerabilities") and source basis ("Built from 225 public bug bounty reports") but lists no concrete actions — "Hunting" is generic, matching the anchor where the domain is named but actions are minimal.

2 / 5

Completeness

Both a "what" (hunting skill for misc vulnerabilities) and an explicit "when" ("Use when hunting misc on any target") are present, but both are vague and the trigger is generic, sitting between the clear-what/weak-when and explicit-both anchors.

3 / 5

Trigger Term Quality

Only a couple of generic keywords ("misc vulnerabilities", "bug bounty reports", "hunting misc") appear; "misc" is a bucket label rather than a phrase a user would naturally say, missing the natural trigger phrasing.

2 / 5

Distinctiveness Conflict Risk

"misc vulnerabilities" is an extremely broad catch-all that overlaps heavily with auth-bypass, ATO, IDOR, and SSRF skills (the skill itself cross-references hunt-saml, hunt-auth-bypass, hunt-ato), giving high overlap risk.

2 / 5

Total

9

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.