CtrlK
BlogDocsLog inGet started
Tessl Logo

src-hunter

实战 SRC / 众测 / Bug bounty 漏洞挖掘工作流 skill。包含:5 阶段方法论(intake → recon → enum → hunt → report)、19 个攻击类 playbook(SQLi/XSS/RCE/SSRF/IDOR/CSRF/Path Traversal/File Upload/SSTI/XXE/Race/HTTP Smuggling/OAuth/JWT/SAML/GraphQL/Mobile/LLM/DoS)、305 个结构化 payload、263 个 WAF/EDR 绕过变体、2887 份 HackerOne 真实 High/Critical 已披露案例、77,000+ WooYun 案例统计、国产 OA / 中间件指纹库、银行 / 电信行业垂直 playbook。当用户提到 "src 挖洞 / src 漏洞挖掘 / bug bounty / 众测 / hackerone / 漏洞赏金 / SRC / 任意 X 漏洞 / 渗透测试" 或问"如何挖某个目标 / 怎么测某个 API / 如何绕过 WAF" 时触发。

73

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable router skill with a clear phased workflow, guardrails, completion checklist, and excellent progressive disclosure into a large verified bundle. The main weakness is conciseness — the playbook table, asset-count table, and directory tree overlap, and the unimplemented CLI-prefix section adds little.

Suggestions

Remove or merge the redundant '数据资产规模' count table and '引用 / 跨链结构' directory tree with the Phase-4 playbook/methodology tables to cut overlapping content.

Drop the 'CLI 助记前缀' section or fold its naming convention into a single line, since the CLI is explicitly unimplemented and it adds no executable value.

Consolidate the repeated compliance red-lines (inline list vs. per-playbook references) into the methodology/evidence-disclosure file and keep only the universal top-level rules inline.

DimensionReasoningScore

Conciseness

The body is a dense operational index with no concept-explainer padding, but it overlaps across the Phase-4 playbook table, the '数据资产规模' count table, and the '引用 / 跨链结构' directory tree, and includes a non-functional 'CLI 助记前缀' section ('当前未实现 CLI, 仅作命名约定'). It is mostly efficient yet could be tightened, matching level 2 rather than the lean level-3 anchor.

2 / 3

Actionability

Provides concrete, executable guidance throughout — named tools per phase (amass/subfinder/httpx/naabu/ffuf/linkfinder/subjack), example dorks ('site:target.com inurl:/admin', 'filetype:env'), test headers ('X-Bug-Bounty: <handle>'), playbook entry hints, and a report skeleton — satisfying the 'concrete, specific guidance' standard for an instruction/router skill.

3 / 3

Workflow Clarity

Clear 5-phase sequence (intake → recon → enum → hunt → report) with per-phase task lists, compliance red-lines as guardrails for destructive ops ('仅 1–3 个 PoC 包, 立即停止'), and a MUST-pass '任务完成自检' checklist plus evidence-discipline reference providing validation checkpoints — clearing the destructive-ops cap.

3 / 3

Progressive Disclosure

SKILL.md is an overview/router pointing one level deep to verified-real references (19 playbooks, 6 methodology, industry, dictionaries, templates, tools) via clearly signaled markdown links and a directory tree; content is appropriately split with easy navigation, matching the level-3 anchor.

3 / 3

Total

11

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete capability list, rich natural-language triggers, and an explicit 'use when' clause covering both what and when. It is third-person and specific with no discernible over-claims beyond quantified asset counts.

DimensionReasoningScore

Specificity

Lists many concrete capabilities — '5 阶段方法论', '19 个攻击类 playbook (SQLi/XSS/RCE/SSRF/IDOR/CSRF/...)', '305 个结构化 payload', '263 个 WAF/EDR 绕过变体', '2887 份 HackerOne 真实 High/Critical 已披露案例', '国产 OA / 中间件指纹库', '银行 / 电信行业垂直 playbook' — matching the 'Lists multiple specific concrete actions' anchor rather than the domain-only level 2.

3 / 3

Completeness

Explicitly answers both what (workflow + asset inventory) and when via the explicit trigger clause '当用户提到 ... 时触发'; not merely implied, so it clears the level-2 cap for missing 'Use when...' guidance.

3 / 3

Trigger Term Quality

Includes natural user phrasing — 'src 挖洞 / src 漏洞挖掘 / bug bounty / 众测 / hackerone / 漏洞赏金 / SRC / 任意 X 漏洞 / 渗透测试' plus intent queries '如何挖某个目标 / 怎么测某个 API / 如何绕过 WAF' — giving good coverage of terms users would actually say, not just jargon.

3 / 3

Distinctiveness Conflict Risk

Targets a clear SRC / bug-bounty niche with distinct, domain-specific triggers unlikely to fire for unrelated skills; well below the generic-conflict level-1 anchor.

3 / 3

Total

12

/

12

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 12 deeper-than-1-level

Warning

referenced_paths_exist

Referenced path issues: 36 deeper-than-1-level

Warning

Total

13

/

16

Passed

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.