CtrlK
BlogDocsLog inGet started
Tessl Logo

src-hunter

实战 SRC / 众测 / Bug bounty 漏洞挖掘工作流 skill。包含:5 阶段方法论(intake → recon → enum → hunt → report)、19 个攻击类 playbook(SQLi/XSS/RCE/SSRF/IDOR/CSRF/Path Traversal/File Upload/SSTI/XXE/Race/HTTP Smuggling/OAuth/JWT/SAML/GraphQL/Mobile/LLM/DoS)、305 个结构化 payload、263 个 WAF/EDR 绕过变体、2887 份 HackerOne 真实 High/Critical 已披露案例、77,000+ WooYun 案例统计、国产 OA / 中间件指纹库、银行 / 电信行业垂直 playbook。当用户提到 "src 挖洞 / src 漏洞挖掘 / bug bounty / 众测 / hackerone / 漏洞赏金 / SRC / 任意 X 漏洞 / 渗透测试" 或问"如何挖某个目标 / 怎么测某个 API / 如何绕过 WAF" 时触发。

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-architected index skill: clear phased workflow with strong validation/safety gating and excellent progressive disclosure into a real bundle. The main improvement area is trimming redundant asset-count and tree sections that duplicate information already present.

DimensionReasoningScore

Conciseness

Mostly efficient tables and pointers that assume Claude's competence, but the '数据资产规模' table repeats counts already in the description and the '引用/跨链结构' tree partly duplicates the reference tables above, which could be trimmed.

4 / 5

Actionability

Provides concrete inline guidance — specific tools (amass/subfinder/httpx/ffuf), dorks ('site:target.com inurl:/admin'), and exact reference paths — with minor gaps since payloads are deliberately deferred to bundled files.

4 / 5

Workflow Clarity

Clear 5-phase sequence (Intake→Recon→Enum→Hunt→Report) with explicit validation checkpoints via the ACTION REQUIRED gating (scope/auth granted check, tool-index verification), safety red-lines for destructive ops, and a completion self-check checklist providing feedback loops.

5 / 5

Progressive Disclosure

SKILL.md is a lean overview that points one level deep to a verified, well-organized bundle (methodology/playbooks/industry/dictionaries/templates/tools/payloader all exist), with references clearly signaled via tables and markdown links for easy navigation.

5 / 5

Total

18

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, highly specific description that comprehensively states capabilities and provides an explicit natural-language trigger clause. The only weakness is the inclusion of a couple of broad terms that slightly raise conflict risk with adjacent pentest skills.

DimensionReasoningScore

Specificity

Enumerates concrete, specific contents — the 5 phases (intake→recon→enum→hunt→report) and 19 named playbook types (SQLi/XSS/RCE/SSRF/IDOR/...) — with comprehensive coverage rather than vague language.

5 / 5

Completeness

Clearly states what the skill does (5-phase workflow + asset inventory) and explicitly when to trigger via the '当用户提到...时触发' clause, answering both what and when.

5 / 5

Trigger Term Quality

Explicit trigger clause lists natural user phrases with synonyms ('src 挖洞 / src 漏洞挖掘 / bug bounty / 漏洞赏金 / 众测 / hackerone / 渗透测试' and '如何挖某个目标 / 怎么测某个 API / 如何绕过 WAF'), covering what users would actually say.

5 / 5

Distinctiveness Conflict Risk

Clear SRC/bug-bounty niche with distinct triggers, but the broad term '渗透测试' and generic '任意 X 漏洞' create minor overlap risk with general pentest/authorization skills rather than minimal conflict.

4 / 5

Total

19

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 12 deeper-than-1-level

Warning

referenced_paths_exist

Referenced path issues: 36 deeper-than-1-level

Warning

Total

13

/

16

Passed

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.