GitHub user

Agent skills by elementalsouls

Every agent skill elementalsouls publishes on GitHub, ranked by score, with the repositories they come from.
skills
19
repositories
2

Repositories by elementalsouls

Skills by elementalsouls, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Skills by elementalsouls, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test.

elementalsouls/Claude-OSINT2.8k—~1.2kAutomated safety check: PassMIT1 mo ago
2

Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

elementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT1 mo ago
3

Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.

elementalsouls/Claude-BugHunter4.8k—~4.5kAutomated safety check: PassMITyesterday
4

Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains.

elementalsouls/Claude-BugHunter4.8k—~3.4kAutomated safety check: PassMITyesterday
5

Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding…

elementalsouls/Claude-BugHunter4.8k—~3.5kAutomated safety check: PassMITyesterday
6

Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). An agent skill from elementalsouls/Claude-BugHunter.

elementalsouls/Claude-BugHunter4.8k—~1.8kAutomated safety check: PassMITyesterday
7

Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g.

elementalsouls/Claude-BugHunter4.8k—~2.3kAutomated safety check: PassMITyesterday
8

Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) — persistent corpus poisoning that survives across sessions and users (distinct from…

elementalsouls/Claude-BugHunter4.8k—~2.6kAutomated safety check: PassMITyesterday
9

Discover a single-page-app's hidden backend API from its public JS bundle, then test that API for broken access control / missing authentication.

elementalsouls/Claude-BugHunter4.8k—~2.2kAutomated safety check: NotesMITyesterday
10

Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10).

elementalsouls/Claude-BugHunter4.8k—~4kAutomated safety check: WarnMITyesterday
11

Hunting skill for auth bypass vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

elementalsouls/Claude-BugHunter4.8k—~8.2kAutomated safety check: PassMITyesterday
12

Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

elementalsouls/Claude-BugHunter4.8k—~5.7kAutomated safety check: PassMITyesterday
13

Hunting skill for sqli vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

elementalsouls/Claude-BugHunter4.8k—~5.5kAutomated safety check: PassMITyesterday
14

Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisible iframe and trick victims into clicking buttons they cannot see (UI redressing).

elementalsouls/Claude-BugHunter4.8k—~1.1kAutomated safety check: PassMITyesterday
15

Hunt mishandling of exceptional conditions — feed an endpoint malformed/unexpected input (wrong type, broken JSON, oversized field, null byte) and make it fail OPEN or leak internals: a verbose…

elementalsouls/Claude-BugHunter4.8k—~786Automated safety check: PassMITyesterday
16

Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise.

elementalsouls/Claude-BugHunter4.8k—~1.9kAutomated safety check: NotesMITyesterday
17

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity…

elementalsouls/Claude-BugHunter4.8k—~5.2kAutomated safety check: PassMITyesterday
18

Hunt Forgot Password / Account Recovery Authentication Flaws — 5 distinct patterns: (1) username enumeration via different responses for valid vs invalid email, (2) reset token exposed directly in…

elementalsouls/Claude-BugHunter4.8k—~1.4kAutomated safety check: PassMITyesterday
19

Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table.

elementalsouls/Claude-BugHunter4.8k—~7.2kAutomated safety check: WarnMITyesterday

Questions, answered from the data.

What is the best skill by elementalsouls?

Run Claude Osint from elementalsouls/Claude-OSINT ranks first of the 19 skills by elementalsouls listed here, with the highest score: its repository has 2.8k GitHub stars, its SKILL.md loads about 1.2k tokens and it passes the automated safety check with no findings. Next come Osint Methodology and Hunt API Misconfig.

Are elementalsouls's skills official?

None yet. All 19 skills by elementalsouls listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.