Agent skill

Detecting Debug Endpoints

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Probe a target for accidentally-public admin / debug / introspection endpoints — Spring Boot Actuator, Apache server-status, Prometheus metrics, GraphQL playground, Swagger UI, phpMyAdmin…

MITAuto-check passedBackend & APIs

Install Detecting Debug Endpoints

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-debug-endpoints -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace detecting-debug-endpoints --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/detecting-debug-endpoints .claude/skills/detecting-debug-endpoints && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detecting-debug-endpoints
GitHub stars
2.8k
Token cost
~2k tokens
SKILL.md length
661 words
Files
4 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Probe a target for accidentally-public admin / debug / introspection endpoints — Spring Boot Actuator, Apache server-status, Prometheus metrics, GraphQL playground, Swagger UI, phpMyAdmin…

  • Works in 4 steps: Confirm Authorization → Run the scanner → Interpret findings → …
  • : post-deploy verification
  • SKILL.md covers Overview, When the skill produces findings, Prerequisites and Instructions, plus 4 more sections
  • Runs Python scripts from its folder; calls python3, jq and php

What it does

Detecting Debug Endpoints is an agent skill from jeremylongshore/tons-of-skills-marketplace. Probe a target for accidentally-public admin / debug / introspection endpoints — Spring Boot Actuator, Apache server-status, Prometheus metrics, GraphQL playground, Swagger UI, phpMyAdmin, JMX-over-HTTP (Jolokia), Elasticsearch cat, Kibana / Grafana / Eureka / Consul panels. Use when: post-deploy verification, security audit before SOC2, inheriting a system you didn't build, or a bug bounty hints at an exposed introspection panel. Threshold: any of the canonical 40+ admin/debug paths returns 200, 302 to a login…

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/PLAYBOOK.md`, `references/THEORY.md` and `scripts/probe_debug.py`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Monitoring and alerting, Backend development and GraphQL. It works with Elasticsearch, Spring Boot, GraphQL and Prometheus. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • : post-deploy verification
  • Security audit before SOC2
  • Inheriting a system you didnt build
  • A bug bounty hints at an exposed introspection panel

Example prompts

  • “check debug endpoints”
  • “actuator exposure”
  • “admin panel scan”
  • “/detecting-debug-endpoints”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Bash(python3:*), Bash(curl:*)

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Confirm Authorization
  2. Run the scanner
  3. Interpret findings
  4. Cross-skill chaining

What it can do on your machine

Read from SKILL.md and the folder at commit 80f86df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash(python3:*)
    • Bash(curl:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • jq
    • php

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Detecting Debug Endpoints loads about 2k tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 199 tokens; SKILL.md has 661 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~199
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit 80f86df, republished under its MIT licence (© jeremylongshore). 661 words, ~2,023 tokens.

Download SKILL.mdSave it as .claude/skills/detecting-debug-endpoints/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
detecting-debug-endpoints
description
Probe a target for accidentally-public admin / debug / introspection endpoints — Spring Boot Actuator, Apache server-status, Prometheus metrics, GraphQL playground, Swagger UI, phpMyAdmin, JMX-over-HTTP (Jolokia), Elasticsearch _cat, Kibana / Grafana / Eureka / Consul panels. Use when: post-deploy verification, security audit before SOC2, inheriting a system you didn't build, or a bug bounty hints at an exposed introspection panel. Threshold: any of the canonical 40+ admin/debug paths returns 200, 302 to a login, or framework-specific JSON shape (e.g., Actuator returning a _links object, server-status HTML body containing the Apache Server Status title). Trigger with: "check debug endpoints", "actuator exposure", "admin panel scan", "graphql playground check".
allowed-tools
Read, Bash(python3:*), Bash(curl:*)
compatibility
Designed for Claude Code
disallowed-tools
Bash(rm:*), Edit(/etc/*)
version
3.30.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
security, information-disclosure, admin-panels, actuator, pentest

Detecting Debug Endpoints

Overview

Modern web stacks ship rich introspection by default. Spring Boot Actuator exposes /actuator/env (every environment variable), /actuator/heapdump (a live heap snapshot that contains credentials), /actuator/jolokia (JMX bean invocation = pre-auth RCE in some configurations). Apache mod_status exposes /server-status with internal IPs, request counts, and the URL of every active request. Prometheus /metrics exposes operational telemetry that often includes connection-string-bearing labels by accident. phpMyAdmin exposes the entire database if unauthenticated.

These are not bugs in the frameworks. They're features that ship enabled-by-default for development convenience and stay enabled in production because nobody disabled them at install time. The probe set covers the canonical 40+ paths and grades each by the response fingerprint specific to that framework.

When the skill produces findings

FindingSeverityThresholdAffected control
Spring Boot Actuator /env exposedCRITICAL200 + body has "propertySources"OWASP A05:2021
Spring Boot Actuator /heapdump exposedCRITICAL200 + Content-Type: application/octet-stream + multi-MB bodyCWE-200
Spring Boot Actuator /jolokia exposedCRITICAL200 + body has "agent":"jolokia"CWE-749
phpMyAdmin reachableCRITICAL200 + HTML body contains "phpMyAdmin" + login formOWASP A07:2021
Prometheus /metrics exposedHIGH200 + body has # HELP or # TYPE linesCWE-200
Apache mod_status exposedHIGH200 + body contains "Apache Server Status"CWE-200
Spring Boot Actuator /actuator indexHIGH200 + body has "_links" JSONOWASP A05:2021
Generic /admin returning 200 (not 401/403)HIGH200 + HTML body with admin-shaped UICWE-285
Elasticsearch _cat exposedHIGH200 + body matches health\s+status\s+indexCWE-200
GraphQL Playground on prodMEDIUM200 + body contains "GraphQLPlayground"CWE-200
Swagger UI on prodMEDIUM200 + body contains "swagger-ui"CWE-200
Spring Boot Actuator /health exposedMEDIUM200 + body has "status":"UP"CWE-200
phpinfo page on prodMEDIUM200 + body has PHP Version headingCWE-200
/robots.txt discloses admin pathsLOW200 + Disallow: lines mentioning /adminCWE-200

Prerequisites

  • Python 3.9+ with requests
  • Authorization for non-local targets

Instructions

Step 1 — Confirm Authorization
text
"Do you have authorization to perform admin / debug endpoint
 discovery on this target? I need confirmation before proceeding."
Step 2 — Run the scanner
bash
python3 ${CLAUDE_PLUGIN_ROOT}/skills/detecting-debug-endpoints/scripts/probe_debug.py \
    https://target.example.com \
    --authorized

Options:

Usage: probe_debug.py URL [OPTIONS]

Options:
  --authorized       Attest authorization (required for non-local)
  --output FILE      Write findings to FILE
  --format FMT       json | jsonl | markdown (default: markdown)
  --min-severity SEV (default: info)
  --timeout SECS     Per-probe timeout (default: 10)
  --paths-file FILE  Override the default probe set with a custom list
  --include-redirects  Treat 302/303 to /login as findings (debug panel
                       exists but auth gates it — still worth noting)

The scanner sends a GET for each path. For 200 responses, it inspects the body for the framework-specific fingerprint to confirm a true positive (not the app's SPA index page). For 302 responses to common login paths, the panel exists but auth is in front — flagged only with --include-redirects.

Step 3 — Interpret findings

CRITICAL = direct compromise vector (env vars / heapdump / Jolokia / phpMyAdmin). Ship same-hour fix: take the endpoint behind authn or disable it. Audit for prior exploitation.

HIGH = information disclosure substantial enough to drive subsequent attacks (server-status reveals request URLs including session tokens in query strings; /metrics labels often contain connection strings; /admin reachable means brute-force can start).

MEDIUM = posture hardening (health checks, swagger).

Show full SKILL.md (239 more words)Show less
Step 4 — Cross-skill chaining

After this skill, suggest:

  • detecting-exposed-secrets-files (#6) — same deploy mistake. If /server-status is reachable, .git/ often is too.
  • auditing-cors-policy (#3) — if a GraphQL or admin endpoint is reachable AND has open CORS, the attack chain compounds.

Examples

Example 1 — Inheriting a system audit

User: "We just acquired example.io. Quick audit of admin surface."

bash
python3 ${CLAUDE_PLUGIN_ROOT}/skills/detecting-debug-endpoints/scripts/probe_debug.py \
    https://example.io --authorized --min-severity medium

Commonly surfaces forgotten /server-status on Apache hosts, /actuator/* left enabled from Spring Boot defaults, leftover /phpmyadmin from initial install.

Example 2 — Spring Boot Actuator paranoia sweep

User: "We use Spring Boot heavily. Show me everywhere Actuator is reachable."

bash
for ENDPOINT in $(cat spring-services.txt); do
  python3 ${CLAUDE_PLUGIN_ROOT}/skills/detecting-debug-endpoints/scripts/probe_debug.py \
      "$ENDPOINT" --authorized --format jsonl
done | jq 'select(.title | contains("Actuator"))'
Example 3 — CI gate against accidental re-enablement
yaml
- name: Debug-endpoint guard
  run: |
    python3 plugins/security/penetration-tester/skills/detecting-debug-endpoints/scripts/probe_debug.py \
        "${{ secrets.STAGING_URL }}" \
        --authorized --min-severity high

Exit 1 fails the deploy if any HIGH or CRITICAL endpoint exposure appears. Catches the regression where a debug profile gets enabled in a application-prod.yml by accident.

Output

JSON / JSONL / Markdown per lib/report.py. Exit codes: 0 clean, 1 high/critical, 2 error.

Error Handling

  • SPA catches every URL with 200 → use --check-only semantics (default: fingerprint check filters out SPA matches).
  • WAF / CDN blocks the scanner → expected for some targets. Coordinate with the target's security team for an allowlist; or run the scanner from inside the target's network if you have authorized internal access.
  • Connection error → exit 2 with underlying error.

Resources

  • references/THEORY.md — Per-framework reasoning: why Actuator, mod_status, Prometheus, GraphQL Playground, Swagger, phpMyAdmin each matter; canonical fingerprints
  • references/PLAYBOOK.md — Per-framework remediation: Spring Boot Actuator authn, Apache mod_status <Location> deny, Prometheus Bearer-token, GraphQL introspection toggle, Swagger profile gate
  • ../analyzing-tls-config/references/AUTHORIZATION.md — Active-scan authorization pattern

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/.curated/detecting-debug-endpoints of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/PLAYBOOK.md
  • references/THEORY.md
  • scripts/probe_debug.py

Open the folder on GitHubat commit 80f86df

Compare with similar skills

Detecting Debug Endpoints next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detecting Debug Endpoints compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detecting Debug Endpoints this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2kAutomated safety check: PassMIT
Oryxos Initoryx-labs/oryxos186—~1.6kAutomated safety check: PassApache-2.0
Implementing API Patternsancoleman/ai-design-components526—~3kAutomated safety check: PassMIT
API Designericrisco/rsc-harness174—~3.1kAutomated safety check: PassMIT
API DesignerJeffallan/claude-skills12k1 repos~2kAutomated safety check: PassMIT
VibexRaja0sama/vibex388—~7.8kAutomated safety check: PassMIT

Similar skills

  • Oryxos Init

    oryx-labs/oryxos

    初始化 OryxOS(或同类 JDK 21 + Spring Boot 3.x 企业级单体)的工程地基:Maven 多模块骨架、 结构化日志、Actuator + Prometheus 监控、Spring MVC + 虚拟线程、springdoc OpenAPI、 统一响应体与全局异常/错误码、Google 格式 + 阿里编码规约(Spotless + 阿里 P3C +…

    186 GitHub stars~1.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Implementing API Patterns

    ancoleman/ai-design-components

    API design and implementation across REST, GraphQL, gRPC, and tRPC patterns.

    526 GitHub stars~3k tokensUpdated 10 mo ago
    Backend & APIsAuto-check passed
  • API Design

    ericrisco/rsc-harness

    A skill your agent uses when settling the contract of an API you expose, before implementation: resources/URLs, REST vs GraphQL, versioning, one RFC 9457 error envelope, pagination, idempotency —…

    174 GitHub stars~3.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 1 repo~2k tokens
    Backend & APIsAuto-check passed
  • Vibex

    Raja0sama/vibex

    Diagrams and checkable docs from a codebase. An agent skill from Raja0sama/vibex.

    388 GitHub stars~7.8k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Spikard

    Goldziher/spikard

    Scaffold Spikard projects and generate code from OpenAPI, AsyncAPI, OpenRPC, GraphQL, and Protobuf schemas using the Spikard CLI or its MCP server.

    123 GitHub stars~799 tokensUpdated 6 days ago
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Detecting Debug Endpoints

What does Detecting Debug Endpoints do?

Probe a target for accidentally-public admin / debug / introspection endpoints — Spring Boot Actuator, Apache server-status, Prometheus metrics, GraphQL playground, Swagger UI, phpMyAdmin…. Detecting Debug Endpoints is an agent skill from jeremylongshore/tons-of-skills-marketplace. Probe a target for accidentally-public admin / debug / introspection endpoints — Spring Boot Actuator, Apache server-status, Prometheus metrics, GraphQL playground, Swagger UI, phpMyAdmin, JMX-over-HTTP (Jolokia), Elasticsearch cat, Kibana / Grafana / Eureka / Consul panels.

When should I use Detecting Debug Endpoints?

Detecting Debug Endpoints fits situations like: : post-deploy verification; security audit before SOC2; inheriting a system you didnt build; A bug bounty hints at an exposed introspection panel.

How do I install Detecting Debug Endpoints in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-debug-endpoints -a claude-code`. Or copy the skill folder (skills/.curated/detecting-debug-endpoints in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/detecting-debug-endpoints in your project. Claude Code loads it when a task matches its description.

How do I install Detecting Debug Endpoints in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-debug-endpoints -a codex`. Or copy the skill folder (skills/.curated/detecting-debug-endpoints in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/detecting-debug-endpoints in your project. Codex loads it when a task matches its description.

Can I use Detecting Debug Endpoints in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-debug-endpoints -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detecting-debug-endpoints, .gemini/skills/detecting-debug-endpoints, .github/skills/detecting-debug-endpoints and .opencode/skills/detecting-debug-endpoints in your project.

What does Detecting Debug Endpoints need to run?

Going by SKILL.md and its folder, Detecting Debug Endpoints needs Python for the scripts in its folder and the command-line tools its instructions call (python3, jq and php). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Bash(python3:*), Bash(curl:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Detecting Debug Endpoints access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Detecting Debug Endpoints safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Detecting Debug Endpoints use?

Detecting Debug Endpoints is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detecting Debug Endpoints use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.4k tokens, read only when the agent opens those files.

What are the alternatives to Detecting Debug Endpoints?

Skills that share tags, products or a category with Detecting Debug Endpoints: Oryxos Init (oryx-labs/oryxos, 186 stars), Implementing API Patterns (ancoleman/ai-design-components, 526 stars), API Design (ericrisco/rsc-harness, 174 stars) and API Designer (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detecting Debug Endpoints?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,825 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 9, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.