CtrlK
BlogDocsLog inGet started
Tessl Logo

hunt-rce

Hunting skill for rce vulnerabilities. Built from 67 public bug bounty reports. Use when hunting rce on any target.

56

Quality

65%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/hunt-rce/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is exceptionally actionable with copy-paste payloads, exact commands, and a well-sequenced methodology backed by explicit validation gates. Its weaknesses are verbosity in narrative/rationale sections and a complete absence of progressive disclosure for a skill whose size clearly warrants reference files.

Suggestions

Move the three "Real Impact Examples", the per-chain "Real shape" historical anecdotes, and "Crown Jewel Targets" rationale into a separate references file to cut narrative padding from the main body.

Extract the CVE deep-dives (Apache 41773/42013, Spring 22963, Jenkins args4j) and the payload/catalog tables into one-level-deep reference files with clearly signaled links.

Tighten remaining prose to payload-plus-command form, dropping justificatory sentences that Claude can already infer.

DimensionReasoningScore

Conciseness

Operational content (payloads, curl commands, gadgets) is lean and assumes Claude's competence, but substantial narrative sections — "Crown Jewel Targets" rationale, three long "Real Impact Examples", and per-chain "Real shape" anecdotes — pad the body beyond what is needed to act.

3 / 5

Actionability

The body is fully executable: copy-paste curl commands with required flags noted, exact exploit headers (e.g. spring.cloud.function.routing-expression SpEL), exact YAML/ViewState gadgets, grep patterns, and OOB callback templates covering the common cases.

5 / 5

Workflow Clarity

A 10-step numbered hunting methodology is clearly sequenced and backed by an explicit "Gate 0 Validation" three-check checklist plus referenced triage-validation gates, giving explicit validation steps and a checklist for a risky testing operation.

5 / 5

Progressive Disclosure

Internal sectioning is clear with good headers, but no bundle files exist and the ~30KB body inlines large CVE deep-dives, chain compositions, and payload catalogs that would naturally live in one-level-deep reference files.

3 / 5

Total

16

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description successfully states both a domain and an explicit use-trigger, but it describes a category rather than concrete capabilities and lacks synonym coverage. It is functional but generic, with elevated overlap risk against sibling hunting skills.

Suggestions

Replace the category phrase "Hunting skill for rce vulnerabilities" with concrete actions, e.g. "Finds and demonstrates remote code execution via command injection, deserialization, and template injection."

Add trigger synonyms users actually say: "Use when hunting for RCE, remote code execution, command injection, or deserialization bugs."

Narrow the over-broad "on any target" trigger to reduce conflict with sibling skills like hunt-ssti and hunt-aspnet.

DimensionReasoningScore

Specificity

The description names the domain ("Hunting skill for rce vulnerabilities") but lists no concrete action verbs; "Built from 67 public bug bounty reports" is provenance, not a capability, so it sits at the anchor where the domain is named but actions are minimal.

2 / 5

Completeness

Both a "what" ("Hunting skill for rce vulnerabilities") and an explicit "when" ("Use when hunting rce on any target") are present, but the "what" is a bare category and the "when" is broad, fitting the anchor where both exist yet could be more specific.

4 / 5

Trigger Term Quality

It includes the natural trigger phrase "Use when hunting rce" but offers no synonyms or variations like "remote code execution", "command injection", or "code execution", matching the anchor with some relevant keywords but missing common variations.

3 / 5

Distinctiveness Conflict Risk

"rce" is a distinct niche but the broad "on any target" phrasing and the skill's own acknowledgment that RCE chains through SSTI/SQLi/SSRF/upload create overlap risk with closely related hunt-* skills.

3 / 5

Total

12

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.