Agent skill

Hunt Core

by Encod3d-Sec in Encod3d-Sec/TORCH

Shared discipline for every hunt- skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop…

MITAuto-check: notesKnowledge Management

Install Hunt Core

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill hunt-core -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH hunt-core --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt/hunt-core .claude/skills/hunt-core && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-core
GitHub stars
329
Token cost
~3.5k tokens
SKILL.md length
1,801 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Shared discipline for every hunt- skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop…

  • Works in 5 steps: Authorization - a program with the… → Scope - exact hosts. *.target.com does… → Exclusions and forbidden techniques -… → …
  • Directly on is this in scope
  • SKILL.md covers Scope gate, Two-account rule, Confirmation gate and Enumeration limits, plus 6 more sections
  • Calls python3 and bash

What it does

Hunt Core is an agent skill from Encod3d-Sec/TORCH. Shared discipline for every hunt- skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop conditions, marker discipline, wiki-first query and self-heal, FIND output, Deadends, and wiki distillation. ALWAYS LOADED alongside any hunt skill. Also trigger directly on "is this in scope", "is this a real bug", "how do I confirm this", "should I keep going", "how many IDs should I test", "what severity", "how do I…

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Knowledge Management, covering Authorization and RBAC. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Directly on is this in scope
  • Is this a real bug
  • How do I confirm this
  • Should I keep going

Example prompts

  • “is this in scope”
  • “is this a real bug”
  • “how do I confirm this”
  • “/hunt-core”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Authorization - a program with the target in scope, a signed agreement, your own lab, or a
  2. Scope - exact hosts. *.target.com does not cover targetapp.io, an acquisition, or
  3. Exclusions and forbidden techniques - check no_bruteforce, scanning caps, DoS, social
  4. Two accounts, both yours - see below. Required for any authorization-class bug.
  5. Deadends - read targets//Deadends.md and skip what is already exhausted.

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt Core loads about 3.5k tokens when it runs. Until then it costs about 167 tokens; SKILL.md has 1,801 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~167
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:189
    | exposed `.git` / `.env` / keys, secrets in a JS bundle | `Skill(hunt-secrets)` |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 1,801 words, ~3,493 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-core/SKILL.md (or your agent's skills folder).
name
hunt-core
description
Shared discipline for every hunt-* skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop conditions, marker discipline, wiki-first query and self-heal, FIND output, Deadends, and wiki distillation. ALWAYS LOADED alongside any hunt skill. Also trigger directly on "is this in scope", "is this a real bug", "how do I confirm this", "should I keep going", "how many IDs should I test", "what severity", "how do I report this", "I got someone else's data". Every hunt-* skill assumes this file; without it they run without their safety and quality layer.

Hunt: Core

The discipline every hunt-* skill assumes. Class-specific technique lives in the hunt skills and the wiki; this file holds what is true regardless of which bug class you are chasing.

Owned here, never repeated in a hunt skill: the scope gate, two-account setup, confirmation gate, enumeration limits, stop conditions, marker discipline, wiki query/self-heal protocol, FIND output, Deadends, and distillation. A hunt skill that restates any of these will drift from this one; reference it instead.

Scope gate

Hunting means reading other people's data, escalating privileges, and creating accounts. Outside an authorized engagement all of it is a crime. Before any request leaves the machine:

  1. Authorization - a program with the target in scope, a signed agreement, your own lab, or a CTF. "Probably fine" is not authorization.
  2. Scope - exact hosts. *.target.com does not cover targetapp.io, an acquisition, or target.com.cdn.net. Read targets/<eng>/scope.md.
  3. Exclusions and forbidden techniques - check no_bruteforce, scanning caps, DoS, social engineering, and any per-program rule before the technique that would violate it.
  4. Two accounts, both yours - see below. Required for any authorization-class bug.
  5. Deadends - read targets/<eng>/Deadends.md and skip what is already exhausted.

Unconfirmed on any of these: ask. Do not infer scope from the fact that a host resolved. Discovery is not authorization. The scope-guard hook enforces the host check on Bash commands; it is a backstop, not the gate.

Two-account rule

Authorization findings are "account A reached account B's object." Without B you have two bad options: test against a real user, or report a guess. Both are worse than not reporting.

  • User A - resource owner. User B - attacker. Separate browser profiles so cookies never cross.
  • Record both internal IDs in targets/<eng>/identities.md as you discover them.
  • Cross-tenant work needs two tenants, not two users in one. Many apps isolate tenants correctly and users not at all.

Confirmation gate

Nothing becomes a FIND on the strength of a response body. The gate is per class; the hunt skill owns the specific "NOT confirmation / IS confirmation" list. Universal rules:

  1. Re-verify in a clean session. Fresh token, new profile, no cached state. If the effect vanishes, you changed your own screen.
  2. Exercise the capability. Not "the server accepted it" but perform the action only the new state permits.
  3. Rule out legitimate access. Before claiming cross-account access, confirm A is not supposed to see it: shared teams, sharing links, public objects, org-wide visibility. The most common false positive in authorization testing.
  4. Blind classes need an OOB HIT. No inference-only findings. The oob.md row must flip to HIT before a FIND is scaffolded.
  5. Reproduce from scratch against your own written steps.

Failed 1-3 is a Deadend, not a "probably real but hard to prove."

[[wiki/techniques/methodology/safe-probing-and-controls]] carries the other half of this gate: how to probe destructive or sensitive surface without touching a real record (use an identifier proven not to exist), and how to fire a control so a NEGATIVE result means something instead of being assumed.

When the hunt spans many hosts, sessions, or parallel agents, the coordination layer adds failure modes this gate does not cover: claims nobody re-checked, requests nobody counted, the same finding filed twice, and severity drifting upward as work is summarised. See [[wiki/techniques/methodology/multi-agent-campaign-orchestration]].

Enumeration limits

Prove the boundary is missing, not how much is behind it.

The server does not check any object. Demonstrating that takes two or three identifiers. A thousand-ID sweep does not raise severity; it collects real users' data and converts a critical finding into an incident report naming you.

  • Default: 5 identifiers. Enough to show a sequential pattern and a missing check.
  • Ceiling without explicit operator approval: 20.
  • Beyond that, and for any range sweep: stop and ask. State why the extra volume changes the finding. Usually it does not.
  • no_bruteforce in scope means range 0. No sweep, no ffuf over an ID list, no exception.
  • Never enumerate writes. Read at volume is a rate problem; write at volume is destruction.

For scale evidence, cite a total field, a pagination header, or a result count. "The response reports 41,180 records; none beyond my two test accounts were retrieved" proves scale without retrieving anything.

Scope of these limits. They govern OBJECT and RECORD enumeration (guessing identifiers to pull other users' data). They do NOT cap legitimate service discovery: an SSRF internal port sweep or a network map is bounded by the engagement RoE (no_dos, scan-rate caps), not by the 5-to-20 object ceiling. Thread it and honor the cap; do not clamp a port sweep to 20.

Stop conditions

Stop and report rather than continuing when:

  • You received real user data. An ID you guessed belonged to someone real, a cache served another session, a beacon fired in a live employee context. Do not re-request to confirm, do not save it, do not use anything in it. Report immediately, state what you received and that you destroyed it, and note it in the FIND rather than hiding it.
  • The next step is destructive or persistent - deleting objects, modifying another tenant's config, planting content that outlives the session.
  • You have a traffic-affecting primitive - desync, cache poisoning, connection-pool effects. The mechanism is the finding.
  • The last step needs volume beyond the limits above.
  • You already have the severity ceiling. More escalation, more risk, no more payout.
  • You left scope. Even one hop. Especially one hop.

Stopping is not failure. "Confirmed and did not exploit" is worth more than a forfeited payout.

Wrong-vector tells (switch the vector, do not tune the tooling). A vector is exhausted the moment it starts fighting you; grinding harder is the sunk-cost trap. Two mechanical signals mean the current vector is the wrong door, not that your tooling needs another pass:

  • The target starves under your own exploit loop (repeated 000 / connection-timeout / empty-reply while you hammer one endpoint). A vector that DoSes a lab box is almost never the intended one. Stop, let it drain, and enumerate a DIFFERENT class (source-read: LFI / alias-traversal / .git / backup; a second service or vhost's own app; OOB creds) before returning.
  • Two verified hashes in a row fail the primary wordlist. The passwords are not wordlist material - they are delivered out-of-band (an email/note/KeePass, a config, a second service). Stop cracking and re-enumerate for where the creds are HANDED OUT; do not extract a third hash. (Engineering around a hostile channel - per-char verify-fix, min-of-2 sampling, gentler pacing - is the tell you are on the wrong vector, not a reason to keep going.)

When a wrong-vector tell fires and the next door is not obvious, call Skill(redteamlead) before grinding further - it reads the engagement state + evidence + wiki and returns ranked directions with an explicit STOP. That is exactly what it is for ("I'm stuck / which vector / should I keep hammering this"); one RTL call at the first sign a vector is fighting back beats hours of sunk-cost grind.

Show full SKILL.md (662 more words)Show less

Marker discipline

Any class where you inject a value and look for it later (xss, ssti, sqli error strings, crlf, log injection, open redirect): use a unique 8+ char alphanumeric canary (e.g. x4hd2k9pq), never test/marker/evil/payload. Check the baseline response for the canary BEFORE claiming reflection; a value already present is not proof you put it there.

Wiki lookup (reference-map first, qmd on a hint)

qmd_query is powerful but ~15-30s per call, so it is a TARGETED deepen, not a pre-attack ritual. Three tiers, in order:

  1. Reference map FIRST (instant Read). Your hunt skill's ## Wiki section names the class's domain MOC + primary page + a few anchors. Read those directly, and one-hop from the MOC for a sibling technique. This answers the anticipated case with zero qmd latency.
  2. qmd_query ONLY on a concrete hint the map does not cover - a specific sink/function (an SSRF-reaching requests.get(user_input)), an observed escape (a <script> context that could be XSS), a fingerprinted version/CVE, or a service the MOC does not list: qmd_query "<the specific thing>" via wiki-search MCP. It auto-surfaces pages added since the skill was written. Do NOT blanket-qmd every action (too slow); do NOT hand-roll from memory when a targeted qmd would answer (that is the opposite failure). Fire it when you have the hint, then act.
  3. Self-heal only if neither the map nor a targeted qmd has it: stub wiki/techniques/<area>/<slug>.md (frontmatter + ## Observed during <engagement>) so the gap fills.

Payload arsenals live in wiki/payloads/. If the MCP is down, bash scripts/wiki-query.sh "<terms>" wraps the same qmd index (-k for an exact CVE/string).

Hunt approaches (which skill for the signal)

hunt-core is the hub: route from the observed signal to the class skill, load it, then use that skill's ## Wiki map. The recon-capture fingerprint router auto-suggests many of these from tool output; this table is the manual reference when it does not fire or you are reasoning about approach.

Signal / surfaceSkill
reflected/stored input, <script> / onerror / javascript: / a DOM sinkSkill(hunt-xss)
a param/body reaching a DB; an error / boolean / time oracleSkill(hunt-sqli)
a URL/host param, a fetch/preview/import sink, ?url=Skill(hunt-ssrf)
an object id, /users/{id}, two-account cross-accessSkill(hunt-idor)
template {{ }} render, XXE (SVG/DOCX/SAML), GraphQLSkill(hunt-injection)
a command sink, template-injection-to-exec, a version+CVESkill(hunt-rce)
a serialized blob (rO0 / AAEAAAD / O:), viewstate, a signed cookieSkill(hunt-deserialization)
login / reset / session / JWT, a legacy-protocol endpointSkill(hunt-auth)
OAuth / SAML redirect_uri or assertionSkill(hunt-federation)
file upload / avatar / document importSkill(hunt-upload)
REST/GraphQL/gRPC, BOLA / BFLA / mass-assignmentSkill(hunt-api)
checkout / price / coupon / workflow logic, a raceSkill(hunt-bizlogic)
CL.TE / TE.CL / HTTP-2 downgrade desyncSkill(hunt-smuggling)
an unkeyed header/param reaching a cacheSkill(hunt-cache)
exposed .git / .env / keys, secrets in a JS bundleSkill(hunt-secrets)
LLM prompt-injection / excessive agencySkill(hunt-llm)
MCP tool-poisoning / indirect injectionSkill(hunt-mcp)
AD: kerberoast / AS-REP / ADCS / DCSync / delegation (dotted-FQDN domain / a DC)Skill(hunt-ad)
Windows LOCAL privesc: service misconfig / autologon reg / SeImpersonate-Potato / scheduled-task / DLL hijack (standalone/workgroup box, or a local shell on a member)Skill(hunt-windows)
AWS/Azure/GCP metadata or IAMSkill(hunt-cloud)
Microsoft 365 / Entra tenantSkill(hunt-m365)
CI/CD pipeline (Actions / runners / OIDC)Skill(hunt-cicd)
macOS TCC / SIP / keychain / XPCSkill(hunt-macos)
SSL-VPN appliance (Fortinet/Citrix/Ivanti/Cisco/PAN)Skill(hunt-vpn)
Modbus / S7 / EtherNet-IP / PLC / HMISkill(hunt-ics)

Process skills (not vuln classes): Skill(ctf-box) boot-to-root, Skill(wiki-recon) external recon, Skill(arsenal) / Skill(wiki-arsenal) tool+payload lookup, Skill(triage) -> Skill(evidence) finding validation, Skill(coverage) untested-class gaps, Skill(next-move) prioritize, Skill(hunt-burp) drive Burp.

FIND output

On confirmation:

Create Vulns/Research/FIND-XXX-SEVERITY-<class>-<host>[-<resource>].md
Add row to Vuln-index.md

Severity is rated on demonstrated impact, not theoretical maximum. Preconditions lower it (victim interaction, an unguessable identifier you cannot show leaking, a race you win one time in twenty). Scale raises it, when you can show the identifier is enumerable without enumerating. State impact in the program's terms (customer data, account security, financial exposure), not in vulnerability classes.

On exhaustion:

Append to Deadends.md: - [ ] <class> on <host> <param/endpoint> -- <why it failed>

The reason matters more than the entry. 403 on cross-account, authorization enforced stops you retesting; a bare entry does not.

Distillation

When a confirmed finding is a reusable technique rather than a target quirk, stage it:

python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page <area>/<page>.md

GENERIC only - no client host, no real identifier, no customer data. Promote later via scripts/wiki-promote.py. Run scripts/check-leaks.sh before any push. Engagement data lives under targets/ and is git-ignored.

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt/hunt-core of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Hunt Core next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Core compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Core this skillEncod3d-Sec/TORCH329—~3.5kAutomated safety check: NotesMIT
Shared Memorysundial-org/awesome-openclaw-skills663—~890Automated safety check: PassNone
Codexqa Code Wikiopenqa-cn/codexqa152—~1.3kAutomated safety check: PassApache-2.0
Logseq Review Workflow Evallogseq/logseq45k—~1kAutomated safety check: PassAGPL-3.0
Baoyu URL To Markdownsdyckjq-lab/llm-wiki-skill2.5k2 repos~3.2kAutomated safety check: PassNone
Obsidian CLIAtmosphere/atmosphere3.8k13 repos~795Automated safety check: PassApache-2.0

Similar skills

  • Shared Memory

    sundial-org/awesome-openclaw-skills

    Share memories and state with other users. An agent skill from sundial-org/awesome-openclaw-skills.

    663 GitHub stars~890 tokensUpdated 7 mo ago
    Knowledge ManagementAuto-check passed
  • Codexqa Code Wiki

    openqa-cn/codexqa

    Builds a local architecture wiki for a repository from the CodexQA symbol graph (no model needed): modules, who calls whom and how often, reading paths, and one self-contained HTML page.

    152 GitHub stars~1.3k tokensUpdated 6 days ago
    Knowledge ManagementAuto-check passed
  • Compare two revisions of the Logseq logseq-review-workflow skill by running the same review prompt against isolated before and after skill snapshots, collecting both outputs, and producing a…

    45k GitHub stars~1k tokensUpdated today
    Knowledge ManagementAuto-check passed
  • Baoyu URL To Markdown

    sdyckjq-lab/llm-wiki-skill

    Fetch any URL and convert to markdown using Chrome CDP. An agent skill from sdyckjq-lab/llm-wiki-skill.

    2.5k GitHub starsUsed in 2 repos~3.2k tokens
    Knowledge ManagementAuto-check passed
  • Obsidian CLI

    Atmosphere/atmosphere

    Interact with Obsidian vaults using the Obsidian CLI to read, create, search, and manage notes, tasks, properties, and more.

    3.8k GitHub starsUsed in 13 repos~795 tokens
    Knowledge ManagementAuto-check passed
  • Esm Cjs Risk Scan

    logseq/logseq

    Scan Logseq ClojureScript Node/Electron targets for npm module loading risks, especially ESM-only packages that may fail when loaded through js/require or shadow-cljs require-based shims.

    45k GitHub stars~3.3k tokensUpdated today
    Knowledge ManagementAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Hunt Core

What does Hunt Core do?

Shared discipline for every hunt- skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop…. Hunt Core is an agent skill from Encod3d-Sec/TORCH. Shared discipline for every hunt- skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop conditions, marker discipline, wiki-first query and self-heal, FIND output, Deadends, and wiki distillation.

When should I use Hunt Core?

Hunt Core fits situations like: directly on is this in scope; is this a real bug; how do I confirm this; should I keep going.

How do I install Hunt Core in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-core -a claude-code`. Or copy the skill folder (skills/hunt/hunt-core in Encod3d-Sec/TORCH) into .claude/skills/hunt-core in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Core in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-core -a codex`. Or copy the skill folder (skills/hunt/hunt-core in Encod3d-Sec/TORCH) into .agents/skills/hunt-core in your project. Codex loads it when a task matches its description.

Can I use Hunt Core in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill hunt-core -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-core, .gemini/skills/hunt-core, .github/skills/hunt-core and .opencode/skills/hunt-core in your project.

What does Hunt Core need to run?

Going by SKILL.md and its folder, Hunt Core needs the command-line tools its instructions call (python3 and bash).

Does Hunt Core access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hunt Core safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Hunt Core use?

Hunt Core is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Core use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Core?

Skills that share tags, products or a category with Hunt Core: Shared Memory (sundial-org/awesome-openclaw-skills, 663 stars), Codexqa Code Wiki (openqa-cn/codexqa, 152 stars), Logseq Review Workflow Eval (logseq/logseq, 45k stars) and Baoyu URL To Markdown (sdyckjq-lab/llm-wiki-skill, 2.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Core?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.