CtrlK
BlogDocsLog inGet started
Tessl Logo

hunt-sharepoint

Hunt Microsoft SharePoint Server (2013/2016/2019/Subscription Edition) on-prem farms — anonymous endpoint enumeration, version disclosure, legacy SOAP login bypass (Authentication.asmx), ToolShell precondition chain (CVE-2025-53770), SafeControl reflection enumeration via Picker.aspx, NTLM Type-2 AD topology disclosure, custom-branding module discovery, EoL farm permanent-CVE-window exploitation, FormDigest anonymous issuance, file-extension blocklist NOT-an-oracle pattern, custom-zone Forms auth bridging on-prem AD. Use when target has SharePoint headers (SPRequestGuid, X-MS-InvokeApp, X-SharePointHealthScore, MicrosoftSharePointTeamServices) or paths (/_layouts/15/, /_vti_bin/, /_api/, /_catalogs/).

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An actionable, well-sequenced hunting skill with concrete commands and a strong validation gate, weakened mainly by redundancy (the ToolShell and download.aspx points recur across sections) and the absence of any progressive-disclosure file split for a long monolithic body.

Suggestions

Dedupe the ToolShell precondition chain and the 'download.aspx is NOT SSRF' discussion so each appears once (e.g. methodology step + one canonical reference), removing the restatements in Payload & Detection, Bypass Techniques, and Real Impact.

Split the CVE/build matrix and the per-endpoint payload patterns into a referenced bundle file (e.g. references/cve-matrix.md) to shorten the SKILL.md overview and add one-level-deep progressive disclosure.

Trim the 'Crown Jewel Targets' market commentary ('one of the richest enterprise attack surfaces in 2025-2026...') to a one-line framing so the body leads with operational content.

DimensionReasoningScore

Conciseness

Mostly high-signal operational detail Claude would not already know, but the ToolShell precondition chain and the 'download.aspx is NOT SSRF' point are restated across Methodology, Payload & Detection, Bypass Techniques, and Real Impact, and the 'Crown Jewel Targets' intro carries market commentary that could be trimmed.

2 / 3

Actionability

Copy-paste-ready curl commands, exact SOAP payloads, concrete endpoints, expected response codes, and grep/jq extraction patterns throughout — fully executable guidance.

3 / 3

Workflow Clarity

A sequenced 10-step methodology is reinforced by an explicit 'Gate 0 Validation' checklist (attacker-impact test, full-chain reproduction requirement, '<10 minutes from a clean shell' reproduce-list, and a retract-SSRF gate).

3 / 3

Progressive Disclosure

No bundle files exist (references/, scripts/, assets/ absent) and the ~430-line body is monolithic; it is well-sectioned but the CVE matrix and detailed payload patterns are inline material that could be split into referenced files.

2 / 3

Total

10

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, well-triggered description that concretely enumerates SharePoint hunt capabilities and provides an explicit 'Use when' clause keyed to recognizable headers and paths. No meaningful weaknesses relative to the rubric.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ('anonymous endpoint enumeration, version disclosure, legacy SOAP login bypass (Authentication.asmx), ToolShell precondition chain (CVE-2025-53770), SafeControl reflection enumeration via Picker.aspx, NTLM Type-2 AD topology disclosure'), far beyond naming a domain plus a few actions.

3 / 3

Completeness

Explicitly answers both 'what' (the enumerated hunt actions) and 'when' via a literal 'Use when target has SharePoint headers ... or paths ...' trigger clause.

3 / 3

Trigger Term Quality

Includes natural and concrete fingerprint terms a SharePoint-hunting user would cite — 'SharePoint headers (SPRequestGuid, X-MS-InvokeApp, X-SharePointHealthScore, MicrosoftSharePointTeamServices)' and paths '/_layouts/15/, /_vti_bin/, /_api/, /_catalogs/'.

3 / 3

Distinctiveness Conflict Risk

Narrow niche (on-prem SharePoint Server 2013/2016/2019/SE) with distinct header/path triggers unlikely to fire for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.