CtrlK
BlogDocsLog inGet started
Tessl Logo

hunt-ssrf

Hunting skill for ssrf vulnerabilities. Built from 15 public bug bounty reports including AWS metadata SSRF (HackerOne $25k Analytics PDF, Shopify Exchange $25k, Capital One 106M-record breach, Dropbox/HelloSign $4,913), GCP metadata SSRF (Snapchat $4k), Azure IMDS SSRF (Azure DevOps $15k chain, ChatGPT Custom Actions MSRC), DNS rebinding SSRF (Concrete CMS, GitLab UrlBlocker), gopher-protocol-to-Redis-RCE (Yahoo Mail $15k), link-preview SSRF (Reddit Matrix $6k), and headless-browser PDF-generator SSRF chains. Use when hunting SSRF on any target — OOB Collaborator confirmation mandatory for blind cases.

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced hunting skill with strong validation gates and concrete payloads throughout. Its main weaknesses are verbosity in narrative sections and a monolithic structure that would benefit from splitting reference material into bundle files.

Suggestions

Move the detailed 'Disclosed Report Citations' and full 'Bypass Techniques' table into a references/ bundle file (e.g. REPORTS.md, BYPASSES.md) and link to them from the body to improve progressive disclosure.

Tighten the 'Real Impact Examples' scenarios into terse cause→payload→impact one-liners instead of multi-sentence narratives to reduce token cost.

Condense 'Common Root Causes' into a compact bulleted list of root-cause patterns without explanatory prose, since the payloads already demonstrate the ideas.

DimensionReasoningScore

Conciseness

Mostly efficient actionable content, but the narrative 'Real Impact Examples' scenarios and prose-style 'Common Root Causes' explanations add padding that could be tightened; it is not the lean 'every token earns its place' anchor.

2 / 3

Actionability

Provides copy-paste-ready bash, Python, and JavaScript payloads, curl/interactsh/ffuf commands, grep patterns, and concrete metadata/internal-port URLs — fully executable, matching the 'fully executable code/commands' anchor.

3 / 3

Workflow Clarity

The 10-step 'Step-by-Step Hunting Methodology' is clearly sequenced, and the OOB-Or-It-Didn't-Happen gate plus 'Gate 0 Validation' checklist provide explicit validation checkpoints and error-recovery feedback (retract claims on zero callbacks), matching the top anchor.

3 / 3

Progressive Disclosure

The skill is a monolithic ~425-line SKILL.md with no bundle files; content that could be split out (detailed report citations, the bypass-technique table, payload catalog) is inline, fitting the 'content that should be separate is inline' anchor rather than the well-signaled one-level-deep reference structure.

2 / 3

Total

10

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description in third-person voice that clearly states the capability and provides an explicit 'Use when' trigger tailored to the SSRF-hunting niche. The only mild weakness is that the long parenthetical enumeration of named reports leans toward verbosity rather than trigger clarity.

DimensionReasoningScore

Specificity

Names the domain ('Hunting skill for ssrf vulnerabilities') and lists multiple concrete subclasses — AWS/GCP/Azure metadata SSRF, DNS rebinding, gopher-to-Redis-RCE, link-preview, headless-browser PDF-generator chains — matching the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

Explicitly answers both what ('Hunting skill for ssrf vulnerabilities' plus enumerated report subclasses) and when ('Use when hunting SSRF on any target — OOB Collaborator confirmation mandatory for blind cases'), satisfying the explicit-trigger anchor.

3 / 3

Trigger Term Quality

Uses natural niche terms a security tester would say ('ssrf', 'SSRF', 'hunting SSRF', 'OOB Collaborator confirmation'), giving good coverage of the terms relevant to invoking this skill.

3 / 3

Distinctiveness Conflict Risk

The SSRF-hunting niche with its OOB-confirmation framing is clearly distinguishable from adjacent skills and unlikely to trigger for the wrong skill.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.