CtrlK
BlogDocsLog inGet started
Tessl Logo

hunt-ssrf

Hunting skill for ssrf vulnerabilities. Built from 15 public bug bounty reports including AWS metadata SSRF (HackerOne $25k Analytics PDF, Shopify Exchange $25k, Capital One 106M-record breach, Dropbox/HelloSign $4,913), GCP metadata SSRF (Snapchat $4k), Azure IMDS SSRF (Azure DevOps $15k chain, ChatGPT Custom Actions MSRC), DNS rebinding SSRF (Concrete CMS, GitLab UrlBlocker), gopher-protocol-to-Redis-RCE (Yahoo Mail $15k), link-preview SSRF (Reddit Matrix $6k), and headless-browser PDF-generator SSRF chains. Use when hunting SSRF on any target — OOB Collaborator confirmation mandatory for blind cases.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/hunt-ssrf/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced SSRF hunting skill with strong validation discipline (the OOB gate is a standout). Its main weaknesses are a monolithic, slightly padded structure with no progressive disclosure to bundle files, and verbose narrative/report-citation sections that inflate token cost.

Suggestions

Split the bulk reference material (Payload & Detection Patterns, Bypass Techniques, Disclosed Report Citations) into separate files under references/ and link to them from SKILL.md so the main file acts as an overview.

Compress the 'Real Impact Examples' narratives and 'Disclosed Report Citations' writeups to one-line summaries with links; drop the full root-cause prose for cases Claude already understands.

Trim restated well-known context (e.g., explanatory sentences in 'Common Root Causes') to keep only the non-obvious operational guidance.

DimensionReasoningScore

Conciseness

Dense, mostly-earning operational content (payloads, bypass catalog, the OOB gate), but the long narrative 'Real Impact Examples' and full 'Disclosed Report Citations' writeups plus some restatement of well-known root causes could be tightened.

3 / 5

Actionability

Copy-paste-ready curl commands, cloud-metadata payloads, a working Python redirect server, JS exfil snippets, grep/ffuf commands, and a bypass catalog fully cover the common SSRF cases.

5 / 5

Workflow Clarity

The OOB gate gives an explicit sequenced workflow with validation checkpoints ('Only after a confirmed callback', 'Run the negative control', per-parameter attribution), feedback loops (retract/retest on zero callbacks, resolve flakiness), and the Gate 0 three-point checklist.

5 / 5

Progressive Disclosure

Section headers and logical flow give good in-file structure, but the ~510-line SKILL.md is monolithic with no bundle files and large inlined reference tables (payloads, bypasses, report citations) that the rubric expects split into one-level-deep referenced files.

3 / 5

Total

16

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has an explicit 'Use when' trigger, clear niche focus, and good domain keywords, but it is padded with a long list of bug-bounty report citations that crowd out crisp capability statements. Tightening the provenance into a brief tail and spelling out 'server-side request forgery' would lift it.

Suggestions

Move the long report-citation list ('Built from 15 public bug bounty reports including ...') to a single concise sentence or a references file, and lead with concrete capabilities the skill performs.

Spell out the synonym 'server-side request forgery' at least once so users who type the full term match the skill.

Add 1-2 more concrete actions (e.g., 'enumerate internal services', 'chain to cloud credential theft') to make the 'what' comprehensive rather than implied.

DimensionReasoningScore

Specificity

Names the domain ('Hunting skill for ssrf vulnerabilities') and a couple concrete actions (hunting SSRF, 'OOB Collaborator confirmation mandatory for blind cases'), but the bulk of the text is report-provenance citations rather than enumerated capabilities, so coverage is not comprehensive.

3 / 5

Completeness

Explicitly answers both what ('Hunting skill for ssrf vulnerabilities') and when ('Use when hunting SSRF on any target ...'); the 'what' is diluted by the long report-citation list, keeping it just short of a clean 5.

4 / 5

Trigger Term Quality

Strong natural keywords a hunter would say ('ssrf', 'ssrf vulnerabilities', 'OOB Collaborator', 'blind cases', plus cloud-metadata/DNS-rebinding/gopher terms), but the spelled-out synonym 'server-side request forgery' is never given.

4 / 5

Distinctiveness Conflict Risk

SSRF hunting is a well-defined niche with a distinct trigger ('Use when hunting SSRF'); while sibling hunt-* skills exist, the SSRF vuln-class trigger is clearly distinguishable with minimal conflict risk.

5 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (514 lines); consider splitting into references/ and linking

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.