Agent skill

Hunt Exceptional Conditions

by elementalsouls in elementalsouls/Claude-BugHunter

Hunt mishandling of exceptional conditions — feed an endpoint malformed/unexpected input (wrong type, broken JSON, oversized field, null byte) and make it fail OPEN or leak internals: a verbose…

MITAuto-check passedDatabases

Install Hunt Exceptional Conditions

skills CLI
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-exceptional-conditions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elementalsouls/Claude-BugHunter hunt-exceptional-conditions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-exceptional-conditions .claude/skills/hunt-exceptional-conditions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-exceptional-conditions
GitHub stars
4.8k
Token cost
~786 tokens
SKILL.md length
289 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Hunt mishandling of exceptional conditions — feed an endpoint malformed/unexpected input (wrong type, broken JSON, oversized field, null byte) and make it fail OPEN or leak internals: a verbose…

  • Tasks that involve Debugging
  • SKILL.md covers What actually pays, Recon, Attack — send what the code… and What counts as a leak (the…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve ORMs and data access

What it does

Hunt Exceptional Conditions is an agent skill from elementalsouls/Claude-BugHunter. Hunt mishandling of exceptional conditions — feed an endpoint malformed/unexpected input (wrong type, broken JSON, oversized field, null byte) and make it fail OPEN or leak internals: a verbose stack-trace / framework error page that discloses ORM internals, server file paths, library versions, or a language traceback. Use on any input-accepting endpoint (JSON APIs, forms, query params). Medium-High when the leak exposes internal structure that arms a deeper attack.

Its SKILL.md is about 790 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases, covering Debugging and ORMs and data access. The repository describes itself as: A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes… The licence is MIT.

When your agent uses it

  • Tasks that involve Debugging
  • Tasks that involve ORMs and data access

Example prompts

  • “/hunt-exceptional-conditions”

What it can do on your machine

Read from SKILL.md and the folder at commit 210aad1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt Exceptional Conditions loads about 786 tokens when it runs. Until then it costs about 125 tokens; SKILL.md has 289 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~125
When it runs · the whole SKILL.md, loaded when a task matches
~786

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elementalsouls/Claude-BugHunter at commit 210aad1, republished under its MIT licence (© elementalsouls). 289 words, ~786 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-exceptional-conditions/SKILL.md (or your agent's skills folder).
name
hunt-exceptional-conditions
description
Hunt mishandling of exceptional conditions — feed an endpoint malformed/unexpected input (wrong type, broken JSON, oversized field, null byte) and make it fail OPEN or leak internals: a verbose stack-trace / framework error page that discloses ORM internals, server file paths, library versions, or a language traceback. Use on any input-accepting endpoint (JSON APIs, forms, query params). Medium-High when the leak exposes internal structure that arms a deeper attack.
report_count
0
sources
hackerone_public

HUNT-EXCEPTIONAL-CONDITIONS — Verbose Errors / Fail-Open (A10:2025)

What actually pays

Well-built apps catch errors and return a clean, generic message. A broken app, when handed input it didn't expect, throws an unhandled exception and renders a developer error page straight to the client — leaking the stack trace, the ORM/query internals, server-side file paths, and framework/library versions. That disclosure is the finding (and it arms SQLi/RCE/path attacks next).

Recon

Any endpoint that parses input is a candidate; the richest are:

JSON APIs that expect typed fields:  POST /api/* with {numbers, ids, enums}
Endpoints with numeric/id path or query params:  /item/{id}, ?page=, ?quantity=
Search / filter / sort params
File or content-type sensitive uploads

Attack — send what the code didn't anticipate

Take a known-good request and break ONE assumption at a time:

  • Wrong type: a field the app expects to be a number/string is sent as an array or object — {"rating":"x","comment":[1,2,3]}, {"quantity":{}}.
  • Malformed body: truncated/!invalid JSON, an unterminated string, a stray brace, a wrong/missing Content-Type.
  • Boundary/oversized: a very long string, a huge/negative/overflow number.
  • Null byte / control chars embedded in a value.
POST /api/Feedbacks   {"rating":"notanumber","comment":[1,2,3]}
GET  /item/' OR /item/%00   (also exercises the error path)

Watch the RESPONSE BODY, not just the status: a 500 (or even a 200/400) whose body contains a stack trace or framework error page is the signal.

What counts as a leak (the success signal)

A finding is confirmed when the response body contains a cross-framework error-disclosure signature:

  • Node/Express + Sequelize: SequelizeDatabaseError, node_modules/sequelize, a JS stack with internal paths.
  • PHP: <b>Warning</b> ... /var/www/.../file.php on line N.
  • Python: Traceback (most recent call last), werkzeug.exceptions.
  • Java: at com.app.Foo(Foo.java:42) stack frames.
  • .NET: Server Error in '/' Application, a [System.XxxException: ...] YSOD.

A clean JSON error ({"error":"Invalid input"}) with no internals is NOT a finding — that's correct handling. Disclosure of internal structure is.

Validation discipline

  • Capture the exact leaked artifact (path, ORM class, version, stack frame) — that's the evidence. "It returned 500" alone is not disclosure.
  • Note what the leak enables next (e.g. a disclosed SQL error → hunt-sqli; a disclosed absolute path → hunt-lfi).

© elementalsouls, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt-exceptional-conditions of elementalsouls/Claude-BugHunter.

Open the folder on GitHubat commit 210aad1

Compare with similar skills

Hunt Exceptional Conditions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Exceptional Conditions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Exceptional Conditions this skillelementalsouls/Claude-BugHunter4.8k—~786Automated safety check: PassMIT
Safe SQL Executionsupabase/supabase111k—~4.2kAutomated safety check: PassApache-2.0
Hybrid Cloud Outboxesgetsentry/sentry46k—~4.8kAutomated safety check: PassCustom licence
Content Create Hero Imageprisma/web1.1k—~6.9kAutomated safety check: PassNone
Sea Orm 2FlyinPancake/yoink112—~2.9kAutomated safety check: PassApache-2.0
Prisma Client APIcurvenote/curvenote1702 repos~1.6kAutomated safety check: PassMIT

Similar skills

  • Safe SQL Execution

    supabase/supabase

    Official

    A skill your agent uses whenever code will build, return, fetch, or execute SQL that runs against a user's real Postgres database — even when the request reads like an ordinary feature or bug fix…

    111k GitHub stars~4.2k tokensUpdated today
    DatabasesAuto-check passed
  • Hybrid Cloud Outboxes

    getsentry/sentry

    Official

    Guide for creating and maintaining outbox-based eventually consistent operations in Sentry.

    46k GitHub stars~4.8k tokensUpdated today
    DatabasesAuto-check passed
  • Official

    A skill your agent uses when the operator wants a hero or meta image for a Prisma blog post; asks to create or generate a blog hero, cover, social card, Open Graph, or YouTube image; mentions cover…

    1.1k GitHub stars~6.9k tokensUpdated today
    DatabasesAuto-check passed
  • Sea Orm 2

    FlyinPancake/yoink

    Expert guidance for SeaORM 2.0, Rust's async ORM with strongly-typed columns, nested ActiveModels, Entity Loader API, and entity-first workflow.

    112 GitHub stars~2.9k tokensUpdated 5 days ago
    DatabasesAuto-check passed
  • Prisma Client API

    curvenote/curvenote

    Prisma Client API reference covering model queries, filters, operators, and client methods.

    170 GitHub starsUsed in 2 repos~1.6k tokens
    DatabasesAuto-check passed
  • DB Migrate

    simstudioai/sim

    Author or review a Drizzle DB migration for zero-downtime safety — expand/contract phasing, backward-compatibility with the deployed app version, and writing the -- migration-safe acknowledgment the…

    30k GitHub stars~2k tokensUpdated today
    DatabasesAuto-check passed

More from elementalsouls/Claude-BugHunter

All 19 skills in this repo
  • Hunt Business Logic

    elementalsouls/Claude-BugHunter

    Hunting skill for business logic vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Hunt API Misconfig

    elementalsouls/Claude-BugHunter

    Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.

    4.8k GitHub stars~4.5k tokensUpdated today
    Auto-check passed
  • Hunt Ato

    elementalsouls/Claude-BugHunter

    Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains.

    4.8k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Hunt Fintech Graphql

    elementalsouls/Claude-BugHunter

    Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding…

    4.8k GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Hunt HTTP Smuggling

    elementalsouls/Claude-BugHunter

    Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Hunt JWT Crypto

    elementalsouls/Claude-BugHunter

    Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g.

    4.8k GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Categories

Questions about Hunt Exceptional Conditions

What does Hunt Exceptional Conditions do?

Hunt mishandling of exceptional conditions — feed an endpoint malformed/unexpected input (wrong type, broken JSON, oversized field, null byte) and make it fail OPEN or leak internals: a verbose…. Hunt Exceptional Conditions is an agent skill from elementalsouls/Claude-BugHunter. Hunt mishandling of exceptional conditions — feed an endpoint malformed/unexpected input (wrong type, broken JSON, oversized field, null byte) and make it fail OPEN or leak internals: a verbose stack-trace / framework error page that discloses ORM internals, server file paths, library versions, or a language traceback.

When should I use Hunt Exceptional Conditions?

Hunt Exceptional Conditions fits situations like: tasks that involve Debugging; tasks that involve ORMs and data access.

How do I install Hunt Exceptional Conditions in Claude Code?

Run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-exceptional-conditions -a claude-code`. Or copy the skill folder (skills/hunt-exceptional-conditions in elementalsouls/Claude-BugHunter) into .claude/skills/hunt-exceptional-conditions in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Exceptional Conditions in Codex?

Run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-exceptional-conditions -a codex`. Or copy the skill folder (skills/hunt-exceptional-conditions in elementalsouls/Claude-BugHunter) into .agents/skills/hunt-exceptional-conditions in your project. Codex loads it when a task matches its description.

Can I use Hunt Exceptional Conditions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-exceptional-conditions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-exceptional-conditions, .gemini/skills/hunt-exceptional-conditions, .github/skills/hunt-exceptional-conditions and .opencode/skills/hunt-exceptional-conditions in your project.

What does Hunt Exceptional Conditions need to run?

SKILL.md names no scripts, command-line tools or credentials: Hunt Exceptional Conditions is instructions for the agent only.

Does Hunt Exceptional Conditions access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hunt Exceptional Conditions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Exceptional Conditions use?

Hunt Exceptional Conditions is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Exceptional Conditions use?

About 786 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Exceptional Conditions?

Skills that share tags, products or a category with Hunt Exceptional Conditions: Safe SQL Execution (supabase/supabase, 111k stars), Hybrid Cloud Outboxes (getsentry/sentry, 46k stars), Content Create Hero Image (prisma/web, 1.1k stars) and Sea Orm 2 (FlyinPancake/yoink, 112 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Exceptional Conditions?

elementalsouls (a GitHub user) maintains it in elementalsouls/Claude-BugHunter, which has 4,846 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 9, 2026.

Source: elementalsouls/Claude-BugHunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.