CtrlK
BlogDocsLog inGet started
Tessl Logo

hunt-sharepoint

Hunt Microsoft SharePoint Server (2013/2016/2019/Subscription Edition) on-prem farms — anonymous endpoint enumeration, version disclosure, legacy SOAP login bypass (Authentication.asmx), ToolShell precondition chain (CVE-2025-53770), SafeControl reflection enumeration via Picker.aspx, NTLM Type-2 AD topology disclosure, custom-branding module discovery, EoL farm permanent-CVE-window exploitation, FormDigest anonymous issuance, file-extension blocklist NOT-an-oracle pattern, custom-zone Forms auth bridging on-prem AD. Use when target has SharePoint headers (SPRequestGuid, X-MS-InvokeApp, X-SharePointHealthScore, MicrosoftSharePointTeamServices) or paths (/_layouts/15/, /_vti_bin/, /_api/, /_catalogs/).

69

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with concrete, executable commands and a clear sequenced methodology backed by validation gates, but it suffers from duplicated blocks across sections and a monolithic single-file structure with no progressive disclosure via bundle files.

Suggestions

De-duplicate the ToolShell 3-step chain, the Picker.aspx recon, and the 'download.aspx is NOT-SSRF' explanation — keep one canonical copy and cross-reference it from the other sections.

Split the long-form material (CVE/build matrix, full Payload & Detection Patterns, and the three Real Impact Examples) into separate reference files under ./references/ and link to them one level deep from SKILL.md to improve progressive disclosure.

Add explicit validate→fix→retry feedback loops at the fragile steps (e.g. Authentication.asmx Mode probe, ToolShell precondition chain) rather than only the final Gate 0 checklist.

DimensionReasoningScore

Conciseness

The body is operational and avoids explaining concepts Claude already knows, but contains noticeable redundancy — the ToolShell 3-step curl block, Picker.aspx recon, and the 'download.aspx is NOT-SSRF' caveat are each repeated across methodology steps, the Payload & Detection Patterns section, Gate 0, and the scenario writeups.

3 / 5

Actionability

Provides fully copy-paste-ready curl commands with exact headers, SOAPAction URIs, complete SOAP XML bodies, exact endpoint paths, and decoded expected responses — covering the common SharePoint hunting cases comprehensively.

5 / 5

Workflow Clarity

A clearly sequenced 10-step methodology plus a Gate 0 Validation checklist with repro-time gates and an explicit 'do not deliver the payload' safety rule; however explicit per-step validate→fix→retry feedback loops are limited rather than pervasive.

4 / 5

Progressive Disclosure

No bundle files exist and all content is inlined into a single ~430-line SKILL.md; section headers give good structure, but the CVE/build matrix, full payload-pattern blocks, and three real-impact scenarios clearly belong in separate reference files.

3 / 5

Total

15

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is excellent: it enumerates concrete SharePoint hunting actions comprehensively, provides explicit trigger guidance via headers and paths, and occupies a distinct niche with named CVEs and endpoints. Third-person voice is maintained throughout.

DimensionReasoningScore

Specificity

Lists many concrete actions (anonymous endpoint enumeration, version disclosure, legacy SOAP login bypass, ToolShell precondition chain, SafeControl reflection enumeration, NTLM Type-2 AD topology disclosure) — comprehensive coverage.

5 / 5

Completeness

Explicitly answers both 'what' (enumerated concrete hunting actions) and 'when' with a clear 'Use when target has SharePoint headers (...) or paths (...)' trigger clause.

5 / 5

Trigger Term Quality

Includes comprehensive natural trigger terms: 'SharePoint Server', header names (SPRequestGuid, X-MS-InvokeApp, X-SharePointHealthScore, MicrosoftSharePointTeamServices) and path patterns (/_layouts/15/, /_vti_bin/, /_api/, /_catalogs/), covering synonyms and file extensions.

5 / 5

Distinctiveness Conflict Risk

Highly specific niche with named CVEs, named endpoints (Authentication.asmx, ToolPane.aspx, Picker.aspx), and named headers — clearly distinguishable from other skills with minimal conflict risk.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.