CtrlK
BlogDocsLog inGet started
Tessl Logo

hunt-source-leak

Hunt source code and build artifact leakage — JavaScript source maps (.js.map) reconstructing TypeScript/ES6 source, Swagger/OpenAPI JSON endpoint discovery, .env/.git exposure, webpack chunks with hardcoded secrets, robots.txt/security.txt recon, build-info files, asset-manifest.json API route discovery, .DS_Store file listing. Use at the START of every recon session — these findings often unlock the entire attack surface.

70

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable and well-phased but suffers from an inlined narrative lesson and tool listings that belong in references, and lacks inline validation checkpoints for a batch-scanning workflow.

Suggestions

Move the Phase 2 engagement anecdote and reporting guidance into a separate references file (e.g. references/source-map-rotation.md), leaving a one-line pointer in SKILL.md to improve progressive_disclosure and conciseness.

Add explicit validation checkpoints between phases (e.g. after Phase 1, 'Review hits for false positives before promoting to findings') to lift workflow_clarity above the batch-skill cap of 3.

Extract the Tools and Chain Table into references/ so the SKILL.md body stays a lean overview.

DimensionReasoningScore

Conciseness

Mostly lean executable commands, but Phase 2's blockquote ("Lesson from an authorized engagement…", "Tell the client this explicitly in the report") is narrative prose that pads the skill with reporting guidance Claude could derive. Efficient overall with minor over-explanation to trim, so above the 3-anchor but not fully lean.

4 / 5

Actionability

Copy-paste ready curl/python/grep pipelines per phase (e.g. the Phase 1 quick-win loop and the Phase 2 source-map extraction python) cover the common cases concretely. Not 4 because examples are executable and complete rather than having minor gaps.

5 / 5

Workflow Clarity

Phases are sequenced 1–7 with a final Validation checklist, but this is a batch-scanning skill with no inline validate→fix→retry checkpoints between phases; the rubric caps batch-operation skills lacking validation at 3. Not 4 because per-phase validation checkpoints are missing.

3 / 5

Progressive Disclosure

No bundle files exist (references/scripts/assets absent) and the skill is a single ~290-line SKILL.md with a long Phase 2 anecdote and tool listings inlined rather than split out. Some section structure exists but content that could be separate is inline, matching the 3-anchor; not 4 because there is no one-level-deep reference split.

3 / 5

Total

15

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, trigger-rich, and explicitly answers both what it does and when to use it, with a sharply defined niche. It is among the strongest examples in the rubric.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ("reconstructing TypeScript/ES6 source", "Swagger/OpenAPI JSON endpoint discovery", ".env/.git exposure", "webpack chunks with hardcoded secrets", ".DS_Store file listing") with comprehensive coverage of leak types. Not the 4-anchor because coverage is broad and specific rather than having only minor gaps.

5 / 5

Completeness

Explicitly answers "what" (the enumerated leak categories) and "when" via the trigger clause "Use at the START of every recon session — these findings often unlock the entire attack surface." Clearly matches the 5-anchor rather than the 4-anchor's softer 'when'.

5 / 5

Trigger Term Quality

Comprehensive natural terms users would say during recon: ".js.map", ".env", ".git", "swagger", "openapi", "robots.txt", "webpack", "asset-manifest.json" — including file extensions and synonyms. Not 4 because nearly all common variations are present.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (source/build artifact leakage recon) with distinct file-extension-based triggers unlikely to fire for unrelated skills. Not 4 because the niche and triggers are sharply differentiated.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.