Hunt Fintech Graphql
sickn33/agentic-awesome-skills
Hunt fintech-specific GraphQL vulnerabilities. An agent skill from sickn33/agentic-awesome-skills.
Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding…
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-fintech-graphql -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elementalsouls/Claude-BugHunter hunt-fintech-graphql --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-fintech-graphql .claude/skills/hunt-fintech-graphql && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hunt-fintech-graphql" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-fintech-graphql into .claude/skills/hunt-fintech-graphql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-fintech-graphql", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-fintech-graphqlType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-fintech-graphql -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elementalsouls/Claude-BugHunter hunt-fintech-graphql --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/hunt-fintech-graphql .agents/skills/hunt-fintech-graphql && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hunt-fintech-graphql" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-fintech-graphql into .agents/skills/hunt-fintech-graphql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-fintech-graphql", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-fintech-graphql -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elementalsouls/Claude-BugHunter hunt-fintech-graphql --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/hunt-fintech-graphql .cursor/skills/hunt-fintech-graphql && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hunt-fintech-graphql" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-fintech-graphql into .cursor/skills/hunt-fintech-graphql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-fintech-graphql", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elementalsouls/Claude-BugHunter.git --path skills/hunt-fintech-graphql--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-fintech-graphql -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elementalsouls/Claude-BugHunter hunt-fintech-graphql --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/hunt-fintech-graphql .gemini/skills/hunt-fintech-graphql && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hunt-fintech-graphql" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-fintech-graphql into .gemini/skills/hunt-fintech-graphql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-fintech-graphql", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elementalsouls/Claude-BugHunter hunt-fintech-graphqlInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-fintech-graphql -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/hunt-fintech-graphql .github/skills/hunt-fintech-graphql && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hunt-fintech-graphql" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-fintech-graphql into .github/skills/hunt-fintech-graphql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-fintech-graphql", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-fintech-graphql -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elementalsouls/Claude-BugHunter hunt-fintech-graphql --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/hunt-fintech-graphql .opencode/skills/hunt-fintech-graphql && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hunt-fintech-graphql" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-fintech-graphql into .opencode/skills/hunt-fintech-graphql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-fintech-graphql", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hunt-fintech-graphqlHunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding…
Hunt Fintech Graphql is an agent skill from elementalsouls/Claude-BugHunter. Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding abuse, idempotency-key bypass enabling double-spend, KYC/PII field-level authorization gaps, and admin-override mutations reachable via mass assignment. Distinct from hunt-graphql, which owns generic GraphQL discovery and IDOR/mutation methodology — this skill owns the delta introduced when a GraphQL layer sits in front of…
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering GraphQL and Banking and insurance. It works with GraphQL. The repository describes itself as: A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes… The licence is MIT.
9 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 8b0f2b3. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are graphql).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Hunt Fintech Graphql loads about 3.5k tokens when it runs. Until then it costs about 226 tokens; SKILL.md has 1,453 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from elementalsouls/Claude-BugHunter at commit 8b0f2b3, republished under its MIT licence (© elementalsouls). 1,453 words, ~3,502 tokens.
.claude/skills/hunt-fintech-graphql/SKILL.md (or your agent's skills folder).Generic GraphQL bugs (IDOR, mass assignment, introspection, batching abuse — see hunt-graphql)
still apply here, but the blast radius changes completely: a resolver bug in a SaaS app leaks
data, the same class of bug in a ledger mutation moves money. Three properties make fintech
GraphQL backends a distinct hunting surface:
transferFunds, redeemRewards, withdrawToBank) can trigger multiple
ledger writes (debit + credit + fee) that must be atomic. GraphQL's flexible input shape and
alias batching make it easy to desynchronize those writes.Float, String, custom
Decimal/Money scalar). How the resolver parses and rounds that value is exploitable surface
in its own right — this barely exists in non-financial GraphQL APIs.User or Account
types commonly expose ssnLast4, routingNumber, kycStatus, governmentIdUrl, or
linkedBankAccount alongside displayName and email — one missing field-level authorization
check on a type used everywhere in the schema fans out to every query that touches it.URL / schema naming patterns (in addition to hunt-graphql's generic /graphql list):
/graphql/ledger
/graphql/payments
/api/wallet/graphql
/internal/ledger-graphql
/banking/graphqlField/type names worth grepping schema introspection or JS bundles for:
balance, availableBalance, pendingBalance, ledgerEntry, ledgerEntries
transferFunds, withdraw, redeem, topUp, reverseTransaction, adjustBalance
kycStatus, ssnLast4, routingNumber, accountNumber, governmentIdUrl
quoteExchangeRate, interestAccrued, rewardsPoints, portfolioValue
idempotencyKey, clientMutationIdTech-stack tells specific to this vertical:
bankLink, plaidLinkToken mutations)ledger or payments subgraph — check for the subgraph's own introspection being reachable directly, bypassing the gateway's stitched-down schemaMoney/Decimal/BigDecimal GraphQL scalar in the schema (scalar Money) — the parser for this scalar is worth fuzzing directlyRun hunt-graphql's discovery + introspection methodology first to get the schema; everything
below assumes you already have (or have partially enumerated) a schema with money-movement types.
Map every mutation that touches balance, whether directly or as a side effect. Not just
transfer*/withdraw* — also redeemRewards, applyCoupon, upgradeTier,
closeAccount (often refunds a balance), disputeTransaction (often provisionally credits).
For each money-movement mutation, identify the ledger write shape. Does one mutation call produce one ledger entry or several (debit sender, credit receiver, fee entry)? Multi-entry writes are the ones worth racing — see Stage 4.
Test idempotency-key handling. Send the identical mutation (same idempotencyKey /
clientMutationId) twice, back-to-back and with a delay. A ledger write on the second call
means idempotency isn't enforced server-side — replay = double-execute.
Test decimal/precision edge cases on every amount-accepting argument — see Payload section. Confirm server-side rounding matches client-displayed rounding; a mismatch is directly monetizable.
Probe cross-account IDOR on account/portfolio node IDs, same as hunt-idor/hunt-graphql,
but specifically test whether a transferFunds-style mutation validates that the
source account belongs to the authenticated caller — not just that some account with
that ID exists. This is the fintech-specific IDOR: authz on the source of a debit is easy to
forget when authz on the destination of a credit was correctly implemented (crediting an
arbitrary account "looks safe" to a developer; debiting one clearly isn't, so it gets checked
— but sometimes only one direction does).
Check field-level authorization on KYC/PII fields by querying the shared User/Account
type from every context that returns it — not just the profile screen. A transaction type
that embeds counterparty { ssnLast4 } is a common place for the check to be missing, because
the developer authorized the top-level transaction query but didn't re-check field access on
the nested counterparty.
Look for admin-tier mutations reachable via mass assignment, not just a missing auth
check — e.g. an input object with a client-settable status or override field that a normal
user's mutation shouldn't expose but that the resolver accepts anyway
(updateTransaction(input: {id, status: "COMPLETED", amount: "..."})).
Test currency-argument consistency. Send a transfer/quote mutation with mismatched
sourceCurrency/targetCurrency combinations the UI never generates (e.g. self-transfer with
a currency conversion) and check whether the resolver's FX-rate lookup and the ledger write use
the same rate — a TOCTOU window here is a direct arbitrage bug.
Combine alias batching with money-movement mutations to test for double-spend — see
hunt-race-condition for the parallel-HTTP escalation once alias batching alone confirms the
resolver isn't serializing writes per-account.
Idempotency-key replay test:
mutation {
transferFunds(input: {
idempotencyKey: "test-key-001"
sourceAccountId: "acc_1"
destAccountId: "acc_2"
amount: "10.00"
}) { transactionId status }
}Send twice with the identical idempotencyKey. Two successful, distinct transactionId values
= idempotency not enforced.
Decimal-precision / rounding probes:
mutation { transferFunds(input: {sourceAccountId:"acc_1", destAccountId:"acc_2", amount: "0.001"}) { transactionId } }
mutation { transferFunds(input: {sourceAccountId:"acc_1", destAccountId:"acc_2", amount: "9999999999999999.99"}) { transactionId } }
mutation { transferFunds(input: {sourceAccountId:"acc_1", destAccountId:"acc_2", amount: "1e2"}) { transactionId } }
mutation { transferFunds(input: {sourceAccountId:"acc_1", destAccountId:"acc_2", amount: "-50.00"}) { transactionId } }Sub-cent amounts test truncate-vs-round handling (repeat N times to accumulate a rounding-error
balance drift); scientific notation and oversized values test whether the Money/Decimal
scalar parser falls back to a native float/int with overflow or precision-loss behavior; negative
amounts test whether the resolver assumes sign server-side or trusts the client's.
Alias-batched double-spend probe (confirm before escalating to parallel HTTP):
mutation {
r1: redeemRewards(input: {rewardId: "rwd_1", accountId: "acc_1"}) { success }
r2: redeemRewards(input: {rewardId: "rwd_1", accountId: "acc_1"}) { success }
r3: redeemRewards(input: {rewardId: "rwd_1", accountId: "acc_1"}) { success }
}If more than one alias succeeds against a single-use reward/coupon, the resolver doesn't
serialize per-account/per-resource writes within a batched request — see hunt-race-condition
for combining this with parallel HTTP POSTs to confirm real double-spend impact.
Source-account authorization probe (asymmetric IDOR check):
mutation {
transferFunds(input: {
sourceAccountId: "VICTIM_ACCOUNT_ID"
destAccountId: "ATTACKER_CONTROLLED_ACCOUNT_ID"
amount: "1.00"
}) { transactionId status }
}Run as the attacker's own session/token. Success = the resolver validated the destination is attacker-controlled (obviously required) but never validated that the source belongs to the caller.
Nested field-level PII probe:
query {
transaction(id: "txn_123") {
amount
counterparty { displayName ssnLast4 routingNumber kycStatus }
}
}Query as a user with no relationship to the counterparty beyond a shared transaction; success on
the nested PII fields is the finding even if the top-level transaction query correctly scoped
the transaction itself.
Mass-assignment probe on admin-shaped input fields:
mutation {
updateTransaction(input: {id: "txn_123", status: "COMPLETED", amount: "0.01"}) { id status }
}Send as a non-admin user against a mutation the client UI never exposes these fields for; a schema that accepts them anyway is mass assignment onto ledger state.
Money/Decimal scalar falls back to native float parsing under edge-case input
(scientific notation, oversized strings), reintroducing floating-point rounding error into a
system that was supposed to guarantee fixed-point precision.User/Account
type's sensitive fields are protected when queried directly (me { ssnLast4 }) but not when
the same type is returned nested inside an unrelated query (transaction { counterparty {...} }).Money-movement findings need a stricter bar than a typical GraphQL IDOR — "the query returns someone else's balance" is real impact; "I sent a malformed amount and got a 400" is not.
200/success response body) is the proof.Money scalar is a
hunt-source-leak-class finding, not a fintech-logic one — don't conflate the two in a report.hunt-graphql — parent skill for generic GraphQL discovery, introspection bypass, node-ID
IDOR, and alias-batching mechanics. Load this skill first; hunt-fintech-graphql assumes that
methodology and only adds the money-movement-specific delta.hunt-business-logic — coupon/reward double-redemption and other logic-flaw patterns
generalize directly to redeemRewards/applyCoupon-style mutations here.hunt-race-condition — the escalation path once alias batching alone confirms a
money-movement mutation doesn't serialize writes: combine with parallel-HTTP / single-packet
attack for a deterministic double-spend PoC.hunt-api-misconfig — mass assignment and JWT-claim tampering patterns apply directly to
admin-shaped GraphQL input objects reachable by normal users.hunt-idor — the source-account-vs-destination-account asymmetric authz pattern (step 5) is
a fintech-specific instance of the general IDOR-on-mutation-argument class.evidence-hygiene — balance screenshots and ledger-entry PoCs need the same cookie/PII
redaction discipline as any other capture, plus care that a real account number/balance from a
live financial account is never included verbatim.triage-validation — apply Gate 0 above before drafting; a fintech program's triage team
will kill anything without a demonstrated ledger state change immediately.© elementalsouls, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/hunt-fintech-graphql of elementalsouls/Claude-BugHunter.
Open the folder on GitHubat commit 8b0f2b3
Hunt Fintech Graphql next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hunt Fintech Graphql this skillelementalsouls/Claude-BugHunter | 4.9k | — | ~3.5k | Automated safety check: Pass | MIT | |
| Hunt Fintech Graphqlsickn33/agentic-awesome-skills | 47k | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Nodejs Backend Patternsever-works/ever-works | 162 | 18 repos | ~4k | Automated safety check: Pass | AGPL-3.0 | |
| API DesignerJeffallan/claude-skills | 12k | 1 repos | ~2k | Automated safety check: Pass | MIT | |
| GraphQL Operations with CodegenChrisWiles/claude-code-showcase | 6.1k | 3 repos | ~1.5k | Automated safety check: Pass | None | |
| API Design Principlesjh941213/my-cc-harness | 125 | 18 repos | ~3.4k | Automated safety check: Pass | None |
sickn33/agentic-awesome-skills
Hunt fintech-specific GraphQL vulnerabilities. An agent skill from sickn33/agentic-awesome-skills.
ever-works/ever-works
Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.
Jeffallan/claude-skills
Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.
ChrisWiles/claude-code-showcase
Sets the rules for writing GraphQL queries and mutations in .gql files, running codegen, and using generated Apollo hooks with proper error and loading handling.
jh941213/my-cc-harness
REST 및 GraphQL API 설계 원칙 가이드. An agent skill from jh941213/my-cc-harness.
dzhalaevd/Donatello
Guides stable API and interface design. An agent skill from dzhalaevd/Donatello.
elementalsouls/Claude-BugHunter
Hunting skill for business logic vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.
elementalsouls/Claude-BugHunter
Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.
elementalsouls/Claude-BugHunter
Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains.
elementalsouls/Claude-BugHunter
Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). An agent skill from elementalsouls/Claude-BugHunter.
elementalsouls/Claude-BugHunter
Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g.
elementalsouls/Claude-BugHunter
Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) — persistent corpus poisoning that survives across sessions and users (distinct from…
Works with
Categories
Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding…. Hunt Fintech Graphql is an agent skill from elementalsouls/Claude-BugHunter. Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding abuse, idempotency-key bypass enabling double-spend, KYC/PII field-level authorization gaps, and admin-override mutations reachable via mass assignment.
Hunt Fintech Graphql fits situations like: hunting a fintech; lending target that exposes a GraphQL API; A schema/response includes balance; account-linking fields.
Run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-fintech-graphql -a claude-code`. Or copy the skill folder (skills/hunt-fintech-graphql in elementalsouls/Claude-BugHunter) into .claude/skills/hunt-fintech-graphql in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-fintech-graphql -a codex`. Or copy the skill folder (skills/hunt-fintech-graphql in elementalsouls/Claude-BugHunter) into .agents/skills/hunt-fintech-graphql in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-fintech-graphql -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-fintech-graphql, .gemini/skills/hunt-fintech-graphql, .github/skills/hunt-fintech-graphql and .opencode/skills/hunt-fintech-graphql in your project.
SKILL.md names no scripts, command-line tools or credentials: Hunt Fintech Graphql is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Hunt Fintech Graphql is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Hunt Fintech Graphql: Hunt Fintech Graphql (sickn33/agentic-awesome-skills, 47k stars), Nodejs Backend Patterns (ever-works/ever-works, 162 stars), API Designer (Jeffallan/claude-skills, 12k stars) and GraphQL Operations with Codegen (ChrisWiles/claude-code-showcase, 6.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elementalsouls (a GitHub user) maintains it in elementalsouls/Claude-BugHunter, which has 4,875 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 10, 2026.
Source: elementalsouls/Claude-BugHunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.