CtrlK
BlogDocsLog inGet started
Tessl Logo

hunt-oauth

Hunting skill for oauth vulnerabilities. Built from 19 public bug bounty reports. Use when hunting oauth on any target.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/hunt-oauth/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with a clear validated workflow, but it is a verbose monolith that should offload payload catalogs and citation lists to reference files.

Suggestions

Condense the 'Crown Jewel Targets' rationale and 'Real Impact Examples' narrative prose into concrete signals and payout figures, removing motivational padding.

Split the payload catalog, disclosed-report citations, and impact scenarios into reference files (e.g. references/payloads.md, references/citations.md) and link them one level deep from SKILL.md.

Fix or remove the dangling reference to docs/verification/phase3-playwright-browser-execution.md, which is not present in this skill's bundle.

DimensionReasoningScore

Conciseness

The body is mostly concrete and domain-specific, but motivational prose ('the trifecta that programs pay most for', 'often security-immature teams') and narrative 'Real Impact Examples' paragraphs could be tightened without losing signal.

2 / 3

Actionability

It provides fully executable curl, adb, and grep commands plus concrete redirect_uri bypass payloads and copy-paste-ready test cases across every methodology step.

3 / 3

Workflow Clarity

A clearly sequenced 10-step methodology ends in a verify-and-document step, reinforced by an explicit Gate 0 validation checklist and a 'headless-test before reporting' checkpoint.

3 / 3

Progressive Disclosure

The ~380-line body is a monolith with good section headers but no bundle files split out, and its one file reference (docs/verification/phase3-playwright-browser-execution.md) does not exist in the skill's bundle.

2 / 3

Total

10

/

12

Passed

Description

75%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is complete and distinct with an explicit 'Use when' trigger, but its capability list is a single vague verb and its trigger-term coverage omits common OAuth-hunting phrasings.

Suggestions

Replace the single vague verb 'Hunting' with concrete capability actions, e.g. 'Test redirect_uri validation, abuse state/nonce CSRF, exploit mobile deep links, and capture OAuth tokens.'

Broaden trigger terms to include natural variations users say: 'OAuth', 'account takeover', 'redirect_uri bypass', 'token theft', 'authorization-code leakage'.

DimensionReasoningScore

Specificity

The description names a clear domain ('oauth vulnerabilities') and a single action ('Hunting'), but does not enumerate concrete capabilities like redirect_uri bypass testing, state/nonce CSRF, or deep-link exploitation, so it is not comprehensive.

2 / 3

Completeness

It answers both what ('Hunting skill for oauth vulnerabilities') and when with an explicit 'Use when hunting oauth on any target' trigger clause, matching the explicit-trigger anchor.

3 / 3

Trigger Term Quality

It includes relevant natural terms ('oauth vulnerabilities', 'hunting', 'bug bounty reports') but misses common variations a user would say such as 'OAuth', 'account takeover', 'redirect_uri', or 'token theft'.

2 / 3

Distinctiveness Conflict Risk

The OAuth-vulnerability niche with a 'hunting oauth' trigger is clearly distinct; though it chains with sibling hunt-* skills, its own trigger is unlikely to fire for the wrong skill.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.