CtrlK
BlogDocsLog inGet started
Tessl Logo

hunt-xxe

Hunting skill for xxe vulnerabilities. Built from 10 public bug bounty reports including SVG-upload XXE, Office-doc (PPTX/DOCX) XXE, SOAP XXE, SAML AssertionConsumer XXE, blind OOB XXE via DTD callback, parameter-entity XXE, XXE-to-LFI, XXE-to-SSRF, and XXE-to-RCE chains (Adobe Commerce CosmicSting CVE-2024-34102). Use when hunting XXE on any target — emphasis on OOB-Or-It-Didn't-Happen Gate for blind cases.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable with excellent workflow gating and payload coverage, but noticeably padded with known concepts and narrative scenarios, and monolithically inlined where a payload library and citation list would benefit from separate reference files.

Suggestions

Trim the 'Real Impact Examples' narratives and 'Common Root Causes' to essentials, or move them to a reference file, to reduce padding Claude doesn't need.

Split the payload library and disclosed-report citations into reference files under references/ and link to them one level deep, improving progressive disclosure.

Promote the buried docs/verification/phase2g-saml-mfa-xxe.md reference into a clearly signaled 'Verification notes' section so the lxml evidence is discoverable.

DimensionReasoningScore

Conciseness

Core material (payloads, parser-ecosystem matrix, methodology, gates) is signal-dense, but several sections are padded with concepts Claude already knows — the bounty-dollar preamble, three narrative 'Real Impact Examples', and 'Common Root Causes' (e.g., copy-paste from StackOverflow).

3 / 5

Actionability

Copy-paste-ready XML payloads, curl commands, grep patterns, concrete URL/header patterns, and specific fingerprint signals cover the common XXE cases fully.

5 / 5

Workflow Clarity

A 10-step methodology is clearly sequenced with explicit validation checkpoints — the Pre-Severity inline-entity probe, the OOB-Or-It-Didn't-Happen feedback loop (no reflection → pivot OOB → error-based fallback), and the 3-question Gate 0 checklist before reporting.

5 / 5

Progressive Disclosure

No bundle files exist (references/scripts/assets empty), yet the single ~415-line SKILL.md inlines content that belongs in separate files (full payload library, 6 report citations, parser matrix); the one external doc reference (docs/verification/phase2g-saml-mfa-xxe.md) is buried in a table cell rather than clearly signaled.

3 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly states both what the skill does and when to use it, with comprehensive coverage of XXE subtypes and a clear niche. Minor gaps are the single governing verb and missing spelled-out 'XML External Entity' trigger synonym.

Suggestions

Add the spelled-out phrase 'XML External Entity' so users who say the full term match the trigger.

Lead with a concrete action verb set (e.g., 'Detect, exploit, and report XXE...') to strengthen specificity beyond the single verb 'Hunting'.

DimensionReasoningScore

Specificity

Lists several concrete XXE subtypes (SVG-upload, Office-doc PPTX/DOCX, SOAP, SAML AssertionConsumer, blind OOB via DTD callback, parameter-entity, XXE-to-LFI/SSRF/RCE) with comprehensive variant coverage, though the governing action is the single verb 'Hunting' rather than a set of distinct verbs.

4 / 5

Completeness

Explicitly answers both 'what' ('Hunting skill for xxe vulnerabilities') and 'when' ('Use when hunting XXE on any target') with concrete trigger phrasing.

5 / 5

Trigger Term Quality

Strong keyword coverage around 'XXE' / 'xxe vulnerabilities' / 'hunting XXE' / 'blind cases' / 'OOB', but the spelled-out phrase 'XML External Entity' and synonyms like 'XML injection' are absent.

4 / 5

Distinctiveness Conflict Risk

XXE is a clear, narrow niche with distinct triggers and named related skills, giving minimal overlap risk with other hunting skills.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.