Shared Memory
sundial-org/awesome-openclaw-skills
Share memories and state with other users. An agent skill from sundial-org/awesome-openclaw-skills.
Shared discipline for every hunt- skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop…
$ npx skills add Encod3d-Sec/TORCH --skill hunt-core -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Encod3d-Sec/TORCH hunt-core --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt/hunt-core .claude/skills/hunt-core && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hunt-core" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-core into .claude/skills/hunt-core/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-core", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-coreType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Encod3d-Sec/TORCH --skill hunt-core -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Encod3d-Sec/TORCH hunt-core --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/hunt/hunt-core .agents/skills/hunt-core && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hunt-core" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-core into .agents/skills/hunt-core/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-core", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Encod3d-Sec/TORCH --skill hunt-core -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Encod3d-Sec/TORCH hunt-core --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/hunt/hunt-core .cursor/skills/hunt-core && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hunt-core" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-core into .cursor/skills/hunt-core/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-core", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Encod3d-Sec/TORCH.git --path skills/hunt/hunt-core--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Encod3d-Sec/TORCH --skill hunt-core -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Encod3d-Sec/TORCH hunt-core --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/hunt/hunt-core .gemini/skills/hunt-core && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hunt-core" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-core into .gemini/skills/hunt-core/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-core", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Encod3d-Sec/TORCH hunt-coreInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Encod3d-Sec/TORCH --skill hunt-core -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/hunt/hunt-core .github/skills/hunt-core && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hunt-core" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-core into .github/skills/hunt-core/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-core", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Encod3d-Sec/TORCH --skill hunt-core -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Encod3d-Sec/TORCH hunt-core --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/hunt/hunt-core .opencode/skills/hunt-core && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hunt-core" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-core into .opencode/skills/hunt-core/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-core", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hunt-coreShared discipline for every hunt- skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop…
Hunt Core is an agent skill from Encod3d-Sec/TORCH. Shared discipline for every hunt- skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop conditions, marker discipline, wiki-first query and self-heal, FIND output, Deadends, and wiki distillation. ALWAYS LOADED alongside any hunt skill. Also trigger directly on "is this in scope", "is this a real bug", "how do I confirm this", "should I keep going", "how many IDs should I test", "what severity", "how do I…
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Knowledge Management, covering Authorization and RBAC. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3bashFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Hunt Core loads about 3.5k tokens when it runs. Until then it costs about 167 tokens; SKILL.md has 1,801 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
| exposed `.git` / `.env` / keys, secrets in a JS bundle | `Skill(hunt-secrets)` |Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 1,801 words, ~3,493 tokens.
.claude/skills/hunt-core/SKILL.md (or your agent's skills folder).The discipline every hunt-* skill assumes. Class-specific technique lives in the hunt skills and
the wiki; this file holds what is true regardless of which bug class you are chasing.
Owned here, never repeated in a hunt skill: the scope gate, two-account setup, confirmation gate, enumeration limits, stop conditions, marker discipline, wiki query/self-heal protocol, FIND output, Deadends, and distillation. A hunt skill that restates any of these will drift from this one; reference it instead.
Hunting means reading other people's data, escalating privileges, and creating accounts. Outside an authorized engagement all of it is a crime. Before any request leaves the machine:
*.target.com does not cover targetapp.io, an acquisition, or
target.com.cdn.net. Read targets/<eng>/scope.md.no_bruteforce, scanning caps, DoS, social
engineering, and any per-program rule before the technique that would violate it.targets/<eng>/Deadends.md and skip what is already exhausted.Unconfirmed on any of these: ask. Do not infer scope from the fact that a host resolved. Discovery
is not authorization. The scope-guard hook enforces the host check on Bash commands; it is a
backstop, not the gate.
Authorization findings are "account A reached account B's object." Without B you have two bad options: test against a real user, or report a guess. Both are worse than not reporting.
targets/<eng>/identities.md as you discover them.Nothing becomes a FIND on the strength of a response body. The gate is per class; the hunt skill owns the specific "NOT confirmation / IS confirmation" list. Universal rules:
oob.md row must flip to
HIT before a FIND is scaffolded.Failed 1-3 is a Deadend, not a "probably real but hard to prove."
[[wiki/techniques/methodology/safe-probing-and-controls]] carries the other half of this gate: how to probe destructive or sensitive surface without touching a real record (use an identifier proven not to exist), and how to fire a control so a NEGATIVE result means something instead of being assumed.
When the hunt spans many hosts, sessions, or parallel agents, the coordination layer adds failure modes this gate does not cover: claims nobody re-checked, requests nobody counted, the same finding filed twice, and severity drifting upward as work is summarised. See [[wiki/techniques/methodology/multi-agent-campaign-orchestration]].
Prove the boundary is missing, not how much is behind it.
The server does not check any object. Demonstrating that takes two or three identifiers. A thousand-ID sweep does not raise severity; it collects real users' data and converts a critical finding into an incident report naming you.
no_bruteforce in scope means range 0. No sweep, no ffuf over an ID list, no exception.For scale evidence, cite a total field, a pagination header, or a result count. "The response
reports 41,180 records; none beyond my two test accounts were retrieved" proves scale without
retrieving anything.
Scope of these limits. They govern OBJECT and RECORD enumeration (guessing identifiers to pull
other users' data). They do NOT cap legitimate service discovery: an SSRF internal port sweep or a
network map is bounded by the engagement RoE (no_dos, scan-rate caps), not by the 5-to-20 object
ceiling. Thread it and honor the cap; do not clamp a port sweep to 20.
Stop and report rather than continuing when:
Stopping is not failure. "Confirmed and did not exploit" is worth more than a forfeited payout.
Wrong-vector tells (switch the vector, do not tune the tooling). A vector is exhausted the moment it starts fighting you; grinding harder is the sunk-cost trap. Two mechanical signals mean the current vector is the wrong door, not that your tooling needs another pass:
000 / connection-timeout /
empty-reply while you hammer one endpoint). A vector that DoSes a lab box is almost never the
intended one. Stop, let it drain, and enumerate a DIFFERENT class (source-read: LFI /
alias-traversal / .git / backup; a second service or vhost's own app; OOB creds) before returning.When a wrong-vector tell fires and the next door is not obvious, call Skill(redteamlead) before
grinding further - it reads the engagement state + evidence + wiki and returns ranked directions with
an explicit STOP. That is exactly what it is for ("I'm stuck / which vector / should I keep hammering
this"); one RTL call at the first sign a vector is fighting back beats hours of sunk-cost grind.
Any class where you inject a value and look for it later (xss, ssti, sqli error strings, crlf, log
injection, open redirect): use a unique 8+ char alphanumeric canary (e.g. x4hd2k9pq), never
test/marker/evil/payload. Check the baseline response for the canary BEFORE claiming
reflection; a value already present is not proof you put it there.
qmd_query is powerful but ~15-30s per call, so it is a TARGETED deepen, not a pre-attack ritual.
Three tiers, in order:
Read). Your hunt skill's ## Wiki section names the class's
domain MOC + primary page + a few anchors. Read those directly, and one-hop from the MOC for a
sibling technique. This answers the anticipated case with zero qmd latency.qmd_query ONLY on a concrete hint the map does not cover - a specific sink/function (an
SSRF-reaching requests.get(user_input)), an observed escape (a <script> context that could be
XSS), a fingerprinted version/CVE, or a service the MOC does not list:
qmd_query "<the specific thing>" via wiki-search MCP. It auto-surfaces pages added since the
skill was written. Do NOT blanket-qmd every action (too slow); do NOT hand-roll from memory when a
targeted qmd would answer (that is the opposite failure). Fire it when you have the hint, then act.wiki/techniques/<area>/<slug>.md (frontmatter + ## Observed during <engagement>) so the gap fills.Payload arsenals live in wiki/payloads/. If the MCP is down, bash scripts/wiki-query.sh "<terms>"
wraps the same qmd index (-k for an exact CVE/string).
hunt-core is the hub: route from the observed signal to the class skill, load it, then use that
skill's ## Wiki map. The recon-capture fingerprint router auto-suggests many of these from tool
output; this table is the manual reference when it does not fire or you are reasoning about approach.
| Signal / surface | Skill |
|---|---|
reflected/stored input, <script> / onerror / javascript: / a DOM sink | Skill(hunt-xss) |
| a param/body reaching a DB; an error / boolean / time oracle | Skill(hunt-sqli) |
a URL/host param, a fetch/preview/import sink, ?url= | Skill(hunt-ssrf) |
an object id, /users/{id}, two-account cross-access | Skill(hunt-idor) |
template {{ }} render, XXE (SVG/DOCX/SAML), GraphQL | Skill(hunt-injection) |
| a command sink, template-injection-to-exec, a version+CVE | Skill(hunt-rce) |
a serialized blob (rO0 / AAEAAAD / O:), viewstate, a signed cookie | Skill(hunt-deserialization) |
| login / reset / session / JWT, a legacy-protocol endpoint | Skill(hunt-auth) |
| OAuth / SAML redirect_uri or assertion | Skill(hunt-federation) |
| file upload / avatar / document import | Skill(hunt-upload) |
| REST/GraphQL/gRPC, BOLA / BFLA / mass-assignment | Skill(hunt-api) |
| checkout / price / coupon / workflow logic, a race | Skill(hunt-bizlogic) |
| CL.TE / TE.CL / HTTP-2 downgrade desync | Skill(hunt-smuggling) |
| an unkeyed header/param reaching a cache | Skill(hunt-cache) |
exposed .git / .env / keys, secrets in a JS bundle | Skill(hunt-secrets) |
| LLM prompt-injection / excessive agency | Skill(hunt-llm) |
| MCP tool-poisoning / indirect injection | Skill(hunt-mcp) |
| AD: kerberoast / AS-REP / ADCS / DCSync / delegation (dotted-FQDN domain / a DC) | Skill(hunt-ad) |
| Windows LOCAL privesc: service misconfig / autologon reg / SeImpersonate-Potato / scheduled-task / DLL hijack (standalone/workgroup box, or a local shell on a member) | Skill(hunt-windows) |
| AWS/Azure/GCP metadata or IAM | Skill(hunt-cloud) |
| Microsoft 365 / Entra tenant | Skill(hunt-m365) |
| CI/CD pipeline (Actions / runners / OIDC) | Skill(hunt-cicd) |
| macOS TCC / SIP / keychain / XPC | Skill(hunt-macos) |
| SSL-VPN appliance (Fortinet/Citrix/Ivanti/Cisco/PAN) | Skill(hunt-vpn) |
| Modbus / S7 / EtherNet-IP / PLC / HMI | Skill(hunt-ics) |
Process skills (not vuln classes): Skill(ctf-box) boot-to-root, Skill(wiki-recon) external recon,
Skill(arsenal) / Skill(wiki-arsenal) tool+payload lookup, Skill(triage) -> Skill(evidence)
finding validation, Skill(coverage) untested-class gaps, Skill(next-move) prioritize,
Skill(hunt-burp) drive Burp.
On confirmation:
Create Vulns/Research/FIND-XXX-SEVERITY-<class>-<host>[-<resource>].md
Add row to Vuln-index.mdSeverity is rated on demonstrated impact, not theoretical maximum. Preconditions lower it (victim interaction, an unguessable identifier you cannot show leaking, a race you win one time in twenty). Scale raises it, when you can show the identifier is enumerable without enumerating. State impact in the program's terms (customer data, account security, financial exposure), not in vulnerability classes.
On exhaustion:
Append to Deadends.md: - [ ] <class> on <host> <param/endpoint> -- <why it failed>The reason matters more than the entry. 403 on cross-account, authorization enforced stops you
retesting; a bare entry does not.
When a confirmed finding is a reusable technique rather than a target quirk, stage it:
python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page <area>/<page>.mdGENERIC only - no client host, no real identifier, no customer data. Promote later via
scripts/wiki-promote.py. Run scripts/check-leaks.sh before any push. Engagement data lives
under targets/ and is git-ignored.
© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/hunt/hunt-core of Encod3d-Sec/TORCH.
Open the folder on GitHubat commit d21b6c9
Hunt Core next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hunt Core this skillEncod3d-Sec/TORCH | 329 | — | ~3.5k | Automated safety check: Notes | MIT | |
| Shared Memorysundial-org/awesome-openclaw-skills | 663 | — | ~890 | Automated safety check: Pass | None | |
| Codexqa Code Wikiopenqa-cn/codexqa | 152 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Logseq Review Workflow Evallogseq/logseq | 45k | — | ~1k | Automated safety check: Pass | AGPL-3.0 | |
| Baoyu URL To Markdownsdyckjq-lab/llm-wiki-skill | 2.5k | 2 repos | ~3.2k | Automated safety check: Pass | None | |
| Obsidian CLIAtmosphere/atmosphere | 3.8k | 13 repos | ~795 | Automated safety check: Pass | Apache-2.0 |
sundial-org/awesome-openclaw-skills
Share memories and state with other users. An agent skill from sundial-org/awesome-openclaw-skills.
openqa-cn/codexqa
Builds a local architecture wiki for a repository from the CodexQA symbol graph (no model needed): modules, who calls whom and how often, reading paths, and one self-contained HTML page.
logseq/logseq
Compare two revisions of the Logseq logseq-review-workflow skill by running the same review prompt against isolated before and after skill snapshots, collecting both outputs, and producing a…
sdyckjq-lab/llm-wiki-skill
Fetch any URL and convert to markdown using Chrome CDP. An agent skill from sdyckjq-lab/llm-wiki-skill.
Atmosphere/atmosphere
Interact with Obsidian vaults using the Obsidian CLI to read, create, search, and manage notes, tasks, properties, and more.
logseq/logseq
Scan Logseq ClojureScript Node/Electron targets for npm module loading risks, especially ESM-only packages that may fail when loaded through js/require or shadow-cljs require-based shims.
Encod3d-Sec/TORCH
Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.
Encod3d-Sec/TORCH
Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.
Encod3d-Sec/TORCH
Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.
Encod3d-Sec/TORCH
Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.
Encod3d-Sec/TORCH
Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.
Encod3d-Sec/TORCH
Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.
Categories
Shared discipline for every hunt- skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop…. Hunt Core is an agent skill from Encod3d-Sec/TORCH. Shared discipline for every hunt- skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop conditions, marker discipline, wiki-first query and self-heal, FIND output, Deadends, and wiki distillation.
Hunt Core fits situations like: directly on is this in scope; is this a real bug; how do I confirm this; should I keep going.
Run `npx skills add Encod3d-Sec/TORCH --skill hunt-core -a claude-code`. Or copy the skill folder (skills/hunt/hunt-core in Encod3d-Sec/TORCH) into .claude/skills/hunt-core in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Encod3d-Sec/TORCH --skill hunt-core -a codex`. Or copy the skill folder (skills/hunt/hunt-core in Encod3d-Sec/TORCH) into .agents/skills/hunt-core in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill hunt-core -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-core, .gemini/skills/hunt-core, .github/skills/hunt-core and .opencode/skills/hunt-core in your project.
Going by SKILL.md and its folder, Hunt Core needs the command-line tools its instructions call (python3 and bash).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Hunt Core is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Hunt Core: Shared Memory (sundial-org/awesome-openclaw-skills, 663 stars), Codexqa Code Wiki (openqa-cn/codexqa, 152 stars), Logseq Review Workflow Eval (logseq/logseq, 45k stars) and Baoyu URL To Markdown (sdyckjq-lab/llm-wiki-skill, 2.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.
Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.