CtrlK
BlogDocsLog inGet started
Tessl Logo

security-arsenal

Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, or bypass techniques. Submittability and the always-rejected / what-NOT-to-submit decision are owned by triage-validation.

67

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, densely-packed offensive-security payload arsenal with copy-paste-ready material across every major vuln class, plus genuinely useful operational validation gates. Its weaknesses are a monolithic single-file structure with no progressive disclosure into bundle files, validation checkpoints that are centralized in operator notes rather than integrated per-workflow, and some self-referential meta-commentary in the Operator Notes that adds tokens without adding payload value.

Suggestions

Split the per-vuln-class payload tables into one-level-deep reference files (e.g. references/xss.md, references/ssrf.md) and keep SKILL.md as a concise overview with clearly-signaled links, improving progressive disclosure from a ~900-line monolith into navigable structure.

Trim self-referential framing from the Operator Notes — remove 'verified in Phase 2H', 'this repo's 31+ skill-area live tests', and similar repo-test metadata that Claude does not need to apply the payloads, retaining only the operational guidance (WAF evaluation order, OOB gate, marker discipline, sampling rule).

Integrate the OOB-confirmation and statistical-sampling validation checkpoints directly into the blind-technique payload sections (blind SQLi, blind SSRF, blind RCE, blind XXE) rather than only stating them once in Operator Notes, so each fragile workflow carries its own inline validate-before-filing checkpoint.

DimensionReasoningScore

Conciseness

The bulk is maximally lean payload/reference tables that earn their tokens, but the 'Operator Notes (Claude-BugHunter)' section carries self-referential padding ('verified in Phase 2H', 'this repo's 31+ skill-area live tests', 'Phase 2D's hardened lab') that Claude does not need. It is not level 3 because not every token earns its place; it is not level 1 because the core reference material is dense and free of basic-concept explanation.

2 / 3

Actionability

The body is almost entirely copy-paste-ready payloads, curl/ffuf/hashcat commands, working Python scripts, and concrete IP-bypass encodings — fully executable, specific examples throughout. It is not level 2 because there is essentially no pseudocode or abstract 'describe-don't-instruct' content; the guidance is concrete and complete.

3 / 3

Workflow Clarity

Several multi-step processes are sequenced (MFA bypass patterns, HTTP smuggling detection, SAML attacks) and strong validation gates exist (OOB-Or-It-Didn't-Happen, statistical sampling with t>3, 'build the chain first, confirm end-to-end, THEN report'), but these checkpoints live only in the Operator Notes rather than being woven into each per-technique workflow, so sequences present lack consistent inline checkpoints. It is not level 3 because validation is not uniformly integrated per workflow; it is not level 1 because explicit checkpoints and a reporting checklist do exist.

2 / 3

Progressive Disclosure

The file is a single ~900-line monolith with no references/, scripts/, or assets/ bundle files; content that could be split into per-vuln-class reference files is all inline, though it is well-organized with clear section headers and a clearly-signaled 'Related Skills & Chains' navigation block. It is not level 3 because there are no one-level-deep reference files offloading detail; it is not level 1 because organization is good and references are not deeply nested.

2 / 3

Total

9

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: third-person voice, a concrete itemized inventory of contents, an explicit 'Use when' trigger covering the common vuln-class terms, and clear disambiguation from the sibling triage-validation skill. It hits the top anchor on every dimension.

DimensionReasoningScore

Specificity

The description enumerates multiple concrete deliverables — 'Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table' — listing specific concrete contents rather than vague actions, matching the level-3 anchor 'Lists multiple specific concrete actions.' It is not level 2 because it goes well beyond naming a domain plus some actions into a comprehensive, itemized inventory.

3 / 3

Completeness

It explicitly answers both 'what' (the arsenal contents) and 'when' via an explicit 'Use when you need specific payloads for...' clause, satisfying the level-3 anchor. It is not capped at 2 because the trigger guidance is explicit, not merely implied.

3 / 3

Trigger Term Quality

The 'Use when' clause surfaces the natural vuln-class terms a tester would actually say — 'XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, or bypass techniques' — giving good coverage of natural trigger terms. It is not level 2 because it lists the full spread of common variations rather than only a few relevant keywords.

3 / 3

Distinctiveness Conflict Risk

The niche is sharply defined as an offensive-security payload library and it even disambiguates ownership ('Submittability and the always-rejected / what-NOT-to-submit decision are owned by triage-validation'), making conflict with sibling skills unlikely. It is not level 2 because the scoped triggers and explicit boundary-setting clearly separate it from adjacent skills.

3 / 3

Total

12

/

12

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (912 lines); consider splitting into references/ and linking

Warning

relative_links

Relative link issues: 1 missing

Warning

Total

14

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.