CtrlK
BlogDocsLog inGet started
Tessl Logo

src-hunter

实战 SRC / 众测 / Bug bounty 漏洞挖掘工作流 skill。包含:5 阶段方法论(intake → recon → enum → hunt → report)、19 个攻击类 playbook(SQLi/XSS/RCE/SSRF/IDOR/CSRF/Path Traversal/File Upload/SSTI/XXE/Race/HTTP Smuggling/OAuth/JWT/SAML/GraphQL/Mobile/LLM/DoS)、305 个结构化 payload、263 个 WAF/EDR 绕过变体、2887 份 HackerOne 真实 High/Critical 已披露案例、77,000+ WooYun 案例统计、国产 OA / 中间件指纹库、银行 / 电信行业垂直 playbook。当用户提到 "src 挖洞 / src 漏洞挖掘 / bug bounty / 众测 / hackerone / 漏洞赏金 / SRC / 任意 X 漏洞 / 渗透测试" 或问"如何挖某个目标 / 怎么测某个 API / 如何绕过 WAF" 时触发。

70

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

87%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-engineered, highly actionable hunting skill body: concrete 5-phase workflow with validation gates and compliance redlines, real verified bundle files behind clear one-level links, and specific tools/payloads rather than abstractions. Minor conciseness and progressive-disclosure gaps come from the inlined inventory table and reference-tree depth.

Suggestions

Trim or relocate the '数据资产规模' inventory table into a reference file so the entry body stays lean; keep only the counts Claude needs for routing.

Note explicitly in the tree diagram that h1-reports/ and payloader/raw JSON are machine-indexed data (not to be read wholesale), to reinforce progressive-disclosure guidance and prevent context blowup.

DimensionReasoningScore

Conciseness

The body is dense and mostly token-efficient — tables, short bullets, and cross-links assume Claude's competence rather than explaining basics — but it carries some inventory padding (the '数据资产规模' table and large reference tree) that could be trimmed, keeping it just below the lean/efficient top anchor.

4 / 5

Actionability

Provides concrete executable guidance throughout: named tools (amass/subfinder/httpx/ffuf/ffuf), exact dorks (`site:target.com inurl:/admin`), specific file pointers per attack type, MCP activation calls (`mcp__jshook__search_tools`), and a copy-ready report skeleton with CVSS 4.0 vector requirement.

5 / 5

Workflow Clarity

A clearly sequenced 5-phase workflow (intake→recon→enum→hunt→report) with explicit validation checkpoints: an ACTION REQUIRED gate (confirm scope.md exists and auth.status=granted), priority routing tied to hit-rate data, compliance redlines as 'don't do' gates, and a completion self-check checklist with feedback loops for a destructive/batch context.

5 / 5

Progressive Disclosure

SKILL.md is an overview with one-level-deep, clearly signaled markdown links to verified real files (methodology/, playbooks/, industry/, dictionaries/, templates/, tools/) and a tree diagram; it is well-organized, though the inlined asset-scale table and the slightly mixed reference/index depth keep it just below the cleanest top anchor.

4 / 5

Total

18

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, inventory-rich description with strong natural trigger-term coverage and a clear distinct niche. Its main weakness is the absence of a clean, explicit 'Use when...' framing — the when-clause is embedded as a trailing trigger list, slightly below the top anchor.

Suggestions

Refactor the trailing trigger list into an explicit 'Use when ...' sentence so the 'when to use' guidance matches the top completeness anchor.

Split the single dense paragraph: lead with a concise one-sentence 'what', then the trigger clause, then the asset inventory, to improve scannability without losing detail.

DimensionReasoningScore

Specificity

Lists multiple concrete concrete actions and assets (5-phase methodology, 19 attack playbooks, 305 payloads, 263 WAF bypass variants, 2887 H1 cases, industry-vertical playbooks), giving comprehensive coverage of what the skill provides.

5 / 5

Completeness

Explicitly states 'what' (the full asset inventory) and provides a 'when' trigger clause ('当用户提到...'), but the 'when' is phrased as a trigger list rather than a clean 'Use when...' clause, and is dense/long; the guideline caps completeness at 3 only when the trigger guidance is missing, so 4 fits.

4 / 5

Trigger Term Quality

Covers natural Chinese and English trigger phrases users would say ('src 挖洞', 'bug bounty', '众测', 'hackerone', '漏洞赏金', '如何挖某个目标', '怎么测某个 API', '如何绕过 WAF') plus synonyms, matching the comprehensive anchor.

5 / 5

Distinctiveness Conflict Risk

Clear niche (real-world SRC/bug-bounty hunting) with distinct trigger vocabulary and an explicit '不应使用本 skill' boundary in the body distinguishing it from code-audit and CTF skills, giving minimal conflict risk.

5 / 5

Total

19

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 12 deeper-than-1-level

Warning

referenced_paths_exist

Referenced path issues: 36 deeper-than-1-level

Warning

Total

13

/

16

Passed

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.