CtrlK
BlogDocsLog inGet started
Tessl Logo

offensive-osint

Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks, curl one-liners for: subdomain enum, GraphQL/Swagger/REST discovery, identity fabric (Entra/Okta/ADFS/Google/SAML/M365 deep — Teams/SharePoint/OneDrive), cloud bucket enum (S3/GCS/Azure), CDN/WAF bypass, origin discovery, vendor fingerprinting (Citrix/F5/Pulse/Fortinet/PaloAlto/Cisco/VMware), CI/CD exposure, 48-pattern secret-scan catalog (AWS/GCP/GitHub/Stripe/Slack/Anthropic/OpenAI/Atlassian/DataDog/npm/PyPI), Postman workspaces, breach correlation (HudsonRock/HIBP/DeHashed/IntelX), TLS/JA3 audit, certificate transparency, JS endpoint extraction, package registry leaks, mobile/APK recon, sat imagery, sector-specific recon (healthcare DICOM, finance SWIFT, ICS/SCADA Modbus/BACnet). Detail content in 15 modular reference files, loaded on demand. Use for any authorized recon: scoping, asset discovery, attack-path mapping, secret triage, severity scoring.

69

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

70%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured lean index with strong progressive disclosure and clear workflows, but it carries a verbose dated changelog and the self-test's section pointers dangle after the v3.0 modular split, hurting actionability.

Suggestions

Rewrite the §49 Self-Test cross-references to point at reference files (e.g. '→ references/secret-patterns.md §17') instead of in-body section numbers (§16.1, §22.8, §23.1) that no longer exist after the v3.0 split.

Collapse the §50 Changelog into a one-line-per-version summary or move full history into a separate CHANGELOG.md reference file; the dated paragraph form pads the skill with time-sensitive content that doesn't aid current execution.

Add a short note near the References Index clarifying that section numbers like §16/§22/§23 referenced elsewhere in the skill correspond to headings inside the reference files, so operators can resolve those pointers.

DimensionReasoningScore

Conciseness

Principle sections (§0–5) are lean and the references table earns its tokens, but the §50 Changelog is ~3 dense paragraphs of dated version history (2026-04-27, 2026-05-02) that is historical context, not operationally needed — the verbosity and time-sensitive content the rubric penalizes outside a deprecated section.

2 / 3

Actionability

Scoring rubrics (§20/§21) and attack-path templates (§39) are concrete and copy-paste ready, but the §49 Self-Test is undermined by dangling cross-references (§16.1, §22.8, §23.1, §27, §46) that no longer resolve in the body after the v3.0 split, so an operator following a prompt cannot locate the referenced material.

2 / 3

Workflow Clarity

'How to use this skill' gives a clear 3-step sequence with per-task loading rules, §0 cleanly separates when/when-not, and the scoring rubrics have explicit thresholds and feedback ('≥70 = accept', 'tagged mobile_review_pending'). No destructive batch step requires a validate→fix→retry loop given the read-only recon posture.

3 / 3

Progressive Disclosure

SKILL.md is a lean overview and the References Index maps each of the 15 files to coverage and trigger phrases with one-level-deep, well-signaled navigation; all cited reference and script files exist on disk.

3 / 3

Total

10

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concrete, comprehensive, and explicitly pairs capabilities with a 'Use for...' trigger clause in third-person voice. It is dense but every term earns its place and trigger coverage is strong.

DimensionReasoningScore

Specificity

Lists many concrete actions — 'subdomain enum', 'GraphQL/Swagger/REST discovery', 'cloud bucket enum (S3/GCS/Azure)', '48-pattern secret-scan catalog', 'TLS/JA3 audit' — matching the 'multiple specific concrete actions' anchor and exceeding the score-2 'some actions' bar.

3 / 3

Completeness

Explicitly answers both what (the full capability list) and when via the trigger clause 'Use for any authorized recon: scoping, asset discovery, attack-path mapping, secret triage, severity scoring.'

3 / 3

Trigger Term Quality

Natural terms users would say are well covered — 'external red-team', 'bug-bounty recon', 'subdomain enum', 'asset discovery', 'secret triage', 'severity scoring' — with good variation rather than jargon-only phrasing.

3 / 3

Distinctiveness Conflict Risk

A clear niche (authorized external red-team/bug-bounty recon, identity fabric, vendor fingerprinting, secret-scan catalog) with distinct triggers unlikely to fire for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.