CtrlK
BlogDocsLog inGet started
Tessl Logo

offensive-osint

Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks, curl one-liners for: subdomain enum, GraphQL/Swagger/REST discovery, identity fabric (Entra/Okta/ADFS/Google/SAML/M365 deep — Teams/SharePoint/OneDrive), cloud bucket enum (S3/GCS/Azure), CDN/WAF bypass, origin discovery, vendor fingerprinting (Citrix/F5/Pulse/Fortinet/PaloAlto/Cisco/VMware), CI/CD exposure, 48-pattern secret-scan catalog (AWS/GCP/GitHub/Stripe/Slack/Anthropic/OpenAI/Atlassian/DataDog/npm/PyPI), Postman workspaces, breach correlation (HudsonRock/HIBP/DeHashed/IntelX), TLS/JA3 audit, certificate transparency, JS endpoint extraction, package registry leaks, mobile/APK recon, sat imagery, sector-specific recon (healthcare DICOM, finance SWIFT, ICS/SCADA Modbus/BACnet). Detail content in 15 modular reference files, loaded on demand. Use for any authorized recon: scoping, asset discovery, attack-path mapping, secret triage, severity scoring.

72

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-architected operational index: highly actionable inline rubrics and attack-path commands, excellent progressive disclosure to 15 real reference files, and a clear load workflow. The main weakness is the verbose, time-sensitive changelog consuming roughly a quarter of the body.

Suggestions

Collapse the §50 Changelog to one-line-per-version entries (or move full detail into a separate CHANGELOG.md) to remove the time-sensitive date/version padding that currently consumes ~25% of the body.

Consider moving the large §39 attack-path hint table (~30 rows) into a reference file, keeping only a short pointer in SKILL.md, to further reduce inline token weight while preserving the anchor role.

Add an explicit validation checkpoint to the "How to use this skill" workflow (e.g., 'confirm confidence level per §2 before emitting a finding') to convert the implicit quality gates into an explicit feedback step.

DimensionReasoningScore

Conciseness

The body is mostly a lean operational index, but the §50 Changelog (~25% of the body) is three long paragraphs of time-sensitive version numbers and dates (2026-04-27) that the rubric explicitly penalizes; trimming it would tighten the whole skill.

3 / 5

Actionability

It provides copy-paste-ready commands throughout (e.g., `kubectl --server=https://{host}:6443 ...`, `etcdctl get / --prefix --keys-only`, `git-dumper`), point-value scoring rubrics in §20/§21, and concrete curl probe targets, fully matching the score-5 anchor.

5 / 5

Workflow Clarity

The "How to use this skill" section gives a clear 3-step load sequence with loading rules of thumb, and §2 confidence levels / §3 output format act as implicit quality gates; minor explicit validation checkpoints in the load workflow keep it just below a 5.

4 / 5

Progressive Disclosure

It is a deliberately lean index pointing to 15 modular reference files (all verified present in references/), surfaced through a well-signaled References Index table mapping file → coverage → trigger phrases, with one-level-deep navigation and bulk data split out of SKILL.md.

5 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exceptionally concrete, third-person description that comprehensively enumerates capabilities and natural trigger terms while explicitly stating when to use it. It is dense rather than padded — nearly every clause is a specific capability or product, so verbosity is not penalized.

DimensionReasoningScore

Specificity

The description lists multiple concrete capabilities ("Concrete probes, wordlists, regexes, dorks, curl one-liners", "subdomain enum", "GraphQL/Swagger/REST discovery", "cloud bucket enum (S3/GCS/Azure)", "48-pattern secret-scan catalog") with comprehensive coverage, matching the score-5 anchor.

5 / 5

Completeness

It explicitly answers both what ("Operational arsenal... Concrete probes, wordlists, regexes...") and when ("Use for any authorized recon: scoping, asset discovery, attack-path mapping, secret triage, severity scoring"), matching the score-5 anchor with concrete trigger phrases.

5 / 5

Trigger Term Quality

It spans natural terms and synonyms a user would actually say ("bug-bounty recon", "subdomain enum", "identity fabric", "certificate transparency", "TLS/JA3 audit") plus product names (Entra/Okta/ADFS, S3/GCS/Azure, Citrix/F5/Pulse), giving comprehensive coverage.

5 / 5

Distinctiveness Conflict Risk

It carves a clear niche (authorized external red-team and bug-bounty recon) with distinct triggers and third-person voice ("Operational arsenal", "Concrete probes"), giving minimal conflict risk with other skills.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.