Search
By elementalsouls
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test. | elementalsouls/ | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 2 | Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. | elementalsouls/ | 2.8k | — | ~8.7k | Automated safety check: Notes | MIT | 1 mo ago |
| 3 | Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering. | elementalsouls/ | 4.8k | — | ~4.5k | Automated safety check: Pass | MIT | yesterday |
| 4 | 4.Hunt Ato Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains. | elementalsouls/ | 4.8k | — | ~3.4k | Automated safety check: Pass | MIT | yesterday |
| 5 | Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding… | elementalsouls/ | 4.8k | — | ~3.5k | Automated safety check: Pass | MIT | yesterday |
| 6 | Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 7 | Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g. | elementalsouls/ | 4.8k | — | ~2.3k | Automated safety check: Pass | MIT | yesterday |
| 8 | Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) — persistent corpus poisoning that survives across sessions and users (distinct from… | elementalsouls/ | 4.8k | — | ~2.6k | Automated safety check: Pass | MIT | yesterday |
| 9 | Discover a single-page-app's hidden backend API from its public JS bundle, then test that API for broken access control / missing authentication. | elementalsouls/ | 4.8k | — | ~2.2k | Automated safety check: Notes | MIT | yesterday |
| 10 | 10.Hunt LLM AI Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). | elementalsouls/ | 4.8k | — | ~4k | Automated safety check: Warn | MIT | yesterday |
| 11 | Hunting skill for auth bypass vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~8.2k | Automated safety check: Pass | MIT | yesterday |
| 12 | Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~5.7k | Automated safety check: Pass | MIT | yesterday |
| 13 | 13.Hunt Sqli Hunting skill for sqli vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~5.5k | Automated safety check: Pass | MIT | yesterday |
| 14 | Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisible iframe and trick victims into clicking buttons they cannot see (UI redressing). | elementalsouls/ | 4.8k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 15 | Hunt mishandling of exceptional conditions — feed an endpoint malformed/unexpected input (wrong type, broken JSON, oversized field, null byte) and make it fail OPEN or leak internals: a verbose… | elementalsouls/ | 4.8k | — | ~786 | Automated safety check: Pass | MIT | yesterday |
| 16 | Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise. | elementalsouls/ | 4.8k | — | ~1.9k | Automated safety check: Notes | MIT | yesterday |
| 17 | Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity… | elementalsouls/ | 4.8k | — | ~5.2k | Automated safety check: Pass | MIT | yesterday |
| 18 | Hunt Forgot Password / Account Recovery Authentication Flaws — 5 distinct patterns: (1) username enumeration via different responses for valid vs invalid email, (2) reset token exposed directly in… | elementalsouls/ | 4.8k | — | ~1.4k | Automated safety check: Pass | MIT | yesterday |
| 19 | Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. | elementalsouls/ | 4.8k | — | ~7.2k | Automated safety check: Warn | MIT | yesterday |