Skill rating
83 skills. The A–F grade combines safety (60%) and quality (40%); tests add a bonus. The rating refreshes automatically from open catalogs.
ManufacturingLogistics and warehouseProcurementQuality controlContact centreField serviceFinanceCustomer supportindustry shortcuts
| # | Grade | Skill | Score ▾ | Safety | Quality | Process | Tests | Popularity | Updated |
|---|---|---|---|---|---|---|---|---|---|
| 51 | B | Hunting skill for subdomain takeover vulnerabilities. Includes modern provider fingerprints — Microsoft Azure DevOps `cloudapp.azure.com` regional-pool re-issue (1-click OAuth ATO via wildcard `reply_ | 99 | 72 | C | — | — | 2 h ago | |
| 52 | B | Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decisi | 95 | 77 | D | — | — | 2 h ago | |
| 53 | B | Hunting skill for oauth vulnerabilities. Built from 19 public bug bounty reports. Use when hunting oauth on any target. | 98 | 72 | C | — | — | 2 h ago | |
| 54 | B | Hunt Kubernetes & Docker — API anonymous access, kubelet 10250 exec (SPDY/WebSocket, NOT plain POST) and the simpler /run primitive, etcd 2379 unauth, dashboard skip-login, RBAC misconfig, secret/SA-t | 93 | 80 | D | — | — | 2 h ago | |
| 55 | B | supply-chain-attack-reconProcedureGitHubDockerInfrastructureSecurityelementalsouls/Claude-BugHunterAgent Skills External recon for software supply-chain attack surface — package-namespace squatting candidates, dependency-confusion vulnerabilities, GitHub Actions injection openings, container image registry expo | 94 | 76 | D | — | — | 2 h ago | |
| 56 | B | Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity override when VRT defaults underrate impact, sev | 99 | 70 | D | — | — | 2 h ago | |
| 57 | B | Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity | 97 | 73 | C | — | — | 2 h ago | |
| 58 | B | Hunt Session Management vulnerabilities — session fixation (no regeneration on login), insufficient invalidation on logout / password-change / email-change, predictable or low-entropy session IDs, JWT | 99 | 70 | D | — | — | 2 h ago | |
| 59 | B | Hunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encrypted), machineKey recovery, dual-parser MAC-bypass anti-pattern, request-validator bypass, trace.axd/elmah.axd disclosure | 99 | 70 | D | — | — | 2 h ago | |
| 60 | B | hunt-sqliProcedureMongoDBSalesforceSecurityData and analyticselementalsouls/Claude-BugHunterAgent Skills Hunting skill for sqli vulnerabilities. Built from 12 public bug bounty reports including modern NoSQL injection (Rocket.Chat CVE-2021-22911 MongoDB $regex, Mongoose ORM CVE-2024-53900 $where bypass), | 97 | 72 | D | — | — | 2 h ago | |
| 61 | B | VMware vSphere / vCenter Server external attack matrix — version fingerprinting, the high-impact CVE chain (CVE-2021-21972 vRealize unauth file upload, CVE-2021-21985 vSAN plugin RCE, CVE-2022-22954 W | 95 | 72 | C | — | — | 2 h ago | |
| 62 | B | hunt-csrfIntegrationStripeGitHubSecurityData and analyticselementalsouls/Claude-BugHunterAgent Skills Hunting skill for csrf vulnerabilities. Built from 15 public bug bounty reports including modern variants — SameSite=Lax sibling-subdomain bypass (Argo CD CVE-2024-22424), GraphQL mutations-via-GET (G | 94 | 75 | B | — | — | 2 h ago | |
| 63 | B | Hunting skill for ssrf vulnerabilities. Built from 15 public bug bounty reports including AWS metadata SSRF (HackerOne $25k Analytics PDF, Shopify Exchange $25k, Capital One 106M-record breach, Dropbo | 95 | 73 | C | — | — | 2 h ago | |
| 64 | B | hunt-auth-bypassProcedureGitHubWordPressSecurityData and analyticselementalsouls/Claude-BugHunterAgent Skills Hunting skill for auth bypass vulnerabilities. Built from 12 public bug bounty reports across SAML XSW / parser-differential (GitHub Enterprise CVE-2025-25291/25292), SAML signature stripping (Uber, R | 95 | 69 | C | — | — | 2 h ago | |
| 65 | B | Hunting skill for idor vulnerabilities. Built from 26 public bug bounty reports. Use when hunting idor on any target. | 95 | 69 | D | — | — | 2 h ago | |
| 66 | B | hunt-miscProcedureGitHubGitLabSoftware developmentData and analyticselementalsouls/Claude-BugHunterAgent Skills Hunting skill for misc vulnerabilities. Built from 225 public bug bounty reports. Use when hunting misc on any target. | 95 | 69 | C | — | — | 2 h ago | |
| 67 | B | Hunting skill for xss vulnerabilities. Built from 174 public bug bounty reports. Use when hunting xss on any target. For markup injection that reflects raw HTML but does NOT execute JavaScript (no `<s | 93 | 72 | C | — | — | 2 h ago | |
| 68 | B | hunt-xxeProcedureWordPowerPointSoftware developmentSecurityelementalsouls/Claude-BugHunterAgent Skills Hunting skill for xxe vulnerabilities. Built from 10 public bug bounty reports including SVG-upload XXE, Office-doc (PPTX/DOCX) XXE, SOAP XXE, SAML AssertionConsumer XXE, blind OOB XXE via DTD callbac | 94 | 70 | D | — | — | 2 h ago | |
| 69 | B | hunt-rceProcedureKubernetesGitHubSecuritySoftware developmentelementalsouls/Claude-BugHunterAgent Skills Hunting skill for rce vulnerabilities. Built from 67 public bug bounty reports. Use when hunting rce on any target. | 91 | 70 | C | — | — | 2 h ago | |
| 70 | C | Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers the 5-stage recon pipeline (seed discovery, asset expansion, enrichment, exposure ana | 92 | 47 | C | — | — | 2 h ago | |
| 71 | C | bug-bountyProcedureGitHubAWSSoftware developmentInfrastructureelementalsouls/Claude-BugHunterAgent Skills Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, | 90 | 38 | C | — | — | 2 h ago | |
| 72 | C | bb-local-toolkitProcedureGitHubAWSSoftware developmentInfrastructureelementalsouls/Claude-BugHunterAgent Skills Local-tooling companion to the bug-bounty orchestrator — carries the SAME complete bug-bounty workflow, but reach for THIS variant when you also need to resolve where tools, wordlists, and clones are | 90 | 35 | C | — | — | 2 h ago | |
| 73 | A | apk-redteam-pipelineProcedureFirebaseAWSMarketingInfrastructureelementalsouls/Claude-BugHunterAgent Skills End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx decompilation, secret/URL/JWT/Firebase grep, pinned-cert extraction, exported-com | 99 | 80 | F will not run | — | — | 2 h ago | |
| 74 | A | Hunt server-side template injection (SSTI) across Jinja2 (Flask/Django), Twig (Symfony), Freemarker (Java), ERB (Rails), Spring, Velocity, Mako, Thymeleaf, Smarty. Detection probes use double-curly an | 100 | 76 | F will not run | — | — | 2 h ago | |
| 75 | B | Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). Cause: front-end proxy and back-end server disagree on where one request ends and the next begins (Content-Length vs Transfer-Encoding header | 99 | 73 | F will not run | — | — | 2 h ago | |
| 76 | B | Client-facing red-team deliverable format — codifies the Subject / Observations / Description / Impact / Recommendation / PoC structure used for external red-team engagements (not bug-bounty platform | 97 | 75 | F will not run | — | — | 2 h ago | |
| 77 | B | web2-reconProcedureGitHubSoftware developmentInfrastructureelementalsouls/Claude-BugHunterAgent Skills Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (Link | 98 | 70 | F will not run | — | — | 2 h ago | |
| 78 | B | Hunt cloud / infrastructure misconfigurations. AWS: public S3 buckets (s3:GetObject anonymous), permissive bucket policies (PutObjectAcl public-write), exposed CloudFront origin, public Lambda functio | 98 | 68 | F will not run | — | — | 2 h ago | |
| 79 | D | offensive-osintProcedureSlackAWSInfrastructureAI and agentselementalsouls/Claude-BugHunterAgent Skillsnot recommended Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks, curl one-liners for: subdomain enum, GraphQL/Swagger/REST discovery, identity fab | 43 | 75 | C | — | — | 2 h ago | |
| 80 | B | Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill si | 99 | 67 | F will not run | — | — | 2 h ago | |
| 81 | B | Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). Patterns: direct injec | 94 | 68 | F will not run | — | — | 2 h ago | |
| 82 | B | security-arsenalProcedureMongoDBMySQLSoftware developmentInfrastructureelementalsouls/Claude-BugHunterAgent Skills Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/comm | 92 | 65 | F will not run | — | — | 2 h ago | |
| 83 | B | Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-discovery privilege analysis. Covers IAM enumeration (aws iam, az role, gcloud iam), | 88 | 67 | F will not run | — | — | 2 h ago |