Agent skill

Info Disclosure Testing

by NeoTheCapt in NeoTheCapt/RedteamAgent

Information disclosure detection — error messages, files, headers, debug endpoints

No licenceAuto-check: notesSecurity

Install Info Disclosure Testing

skills CLI
$ npx skills add NeoTheCapt/RedteamAgent --skill info-disclosure-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NeoTheCapt/RedteamAgent info-disclosure-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NeoTheCapt/RedteamAgent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent/skills/info-disclosure-testing .claude/skills/info-disclosure-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
info-disclosure-testing
GitHub stars
142
Token cost
~1.1k tokens
SKILL.md length
450 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
None found

At a glance

Information disclosure detection — error messages, files, headers, debug endpoints

  • Works in 8 steps: HTTP Header Analysis → Error Message Analysis → Sensitive File Discovery → …
  • Tasks that involve Penetration testing
  • SKILL.md covers When to Activate, Tools, Methodology and What to Record
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Info Disclosure Testing is an agent skill from NeoTheCapt/RedteamAgent. Information disclosure detection — error messages, files, headers, debug endpoints

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Penetration testing. It works with PHP, Git and SQL. The repository describes itself as: An AI red-team agent for authorized labs and web app pentesting workflows. Turns Claude Code / OpenCode / Codex into a structured recon → test → exploit → report workflow, with…

When your agent uses it

  • Tasks that involve Penetration testing

Example prompts

  • “/info-disclosure-testing”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. HTTP Header Analysis
  2. Error Message Analysis
  3. Sensitive File Discovery
  4. Backup and Temporary Files
  5. Debug and Admin Endpoints
  6. API Response Analysis
  7. Client-Side Disclosure
  8. Version and Technology Detection

What it can do on your machine

Read from SKILL.md and the folder at commit 2e60476. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Info Disclosure Testing loads about 1.1k tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 450 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:48
    - [ ] `/.env` — environment variables, database credentials, API keys

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 450 words (~1,091 tokens).

name
info-disclosure-testing
origin
RedteamOpencode

Read the full SKILL.md on GitHub

Files

Just SKILL.md in agent/skills/info-disclosure-testing of NeoTheCapt/RedteamAgent.

Open the folder on GitHubat commit 2e60476

Compare with similar skills

Info Disclosure Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Info Disclosure Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Info Disclosure Testing this skillNeoTheCapt/RedteamAgent142—~1.1kAutomated safety check: NotesNone
Source Leak Huntuphiago/recon-skills1.3k—~2.2kAutomated safety check: NotesMIT
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Php Audit Pipeline0xShe/PHP-Code-Audit-Skill4021 repos~4.9kAutomated safety check: PassNone
Code Security AuditProgrammerAnthony/Expert-Coding-Harness235—~1.6kAutomated safety check: PassMIT
Php Codeigniter Audit0xShe/PHP-Code-Audit-Skill4021 repos~477Automated safety check: PassNone

Similar skills

  • Source Leak Hunt

    uphiago/recon-skills

    Mass scan for exposed env files, backups, and git configs. An agent skill from uphiago/recon-skills.

    1.3k GitHub stars~2.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Php Audit Pipeline

    0xShe/PHP-Code-Audit-Skill

    PHP Web 全链路白盒代码安全审计流水线(多文件版编排)。作为总编排参考,按 Sink 类型调用各子审计 skill(php-route-mapper/php-auth-audit/php-route-tracer/php--audit),并复用统一输出与分级标准。

    402 GitHub starsUsed in 1 repo~4.9k tokens
    SecurityAuto-check passed
  • Code Security Audit

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…

    235 GitHub stars~1.6k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Php Codeigniter Audit

    0xShe/PHP-Code-Audit-Skill

    CodeIgniter 框架特效安全审计工具。针对 CodeIgniter 的 CSRF、XSS 输出过滤、数据库查询构造、路由与验证器配置、会话 Cookie 安全等机制进行白盒静态审计,并映射到通用漏洞类型体系(CSRF/AUTH/XSS/SQL/CFG/SESS 等)。

    402 GitHub starsUsed in 1 repo~477 tokens
    SecurityAuto-check passed
  • Ssti

    PentesterFlow/agent

    Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or…

    1.4k GitHub stars~1.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from NeoTheCapt/RedteamAgent

All 25 skills in this repo
  • Auth Bypass

    NeoTheCapt/RedteamAgent

    Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses

    142 GitHub stars~1.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Business Logic Testing

    NeoTheCapt/RedteamAgent

    Business logic vulnerability detection — workflow bypass, price manipulation, state abuse, and application-specific flaws

    142 GitHub stars~2.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Cors Testing

    NeoTheCapt/RedteamAgent

    CORS misconfiguration testing for data theft and access control bypass

    142 GitHub stars~904 tokensUpdated 2 mo ago
    Auto-check passed
  • Csrf Testing

    NeoTheCapt/RedteamAgent

    Cross-site request forgery testing for state-changing operations

    142 GitHub stars~791 tokensUpdated 2 mo ago
    Auto-check passed
  • Deserialization Testing

    NeoTheCapt/RedteamAgent

    Insecure deserialization detection and gadget chain exploitation

    142 GitHub stars~836 tokensUpdated 2 mo ago
    Auto-check passed
  • Directory Fuzzing

    NeoTheCapt/RedteamAgent

    Discover hidden directories, files, and endpoints on a web server

    142 GitHub stars~737 tokensUpdated 2 mo ago
    Auto-check: notes

Works with

Categories

Questions about Info Disclosure Testing

What does Info Disclosure Testing do?

Information disclosure detection — error messages, files, headers, debug endpoints. Info Disclosure Testing is an agent skill from NeoTheCapt/RedteamAgent.

When should I use Info Disclosure Testing?

Info Disclosure Testing fits situations like: tasks that involve Penetration testing.

How do I install Info Disclosure Testing in Claude Code?

Run `npx skills add NeoTheCapt/RedteamAgent --skill info-disclosure-testing -a claude-code`. Or copy the skill folder (agent/skills/info-disclosure-testing in NeoTheCapt/RedteamAgent) into .claude/skills/info-disclosure-testing in your project. Claude Code loads it when a task matches its description.

How do I install Info Disclosure Testing in Codex?

Run `npx skills add NeoTheCapt/RedteamAgent --skill info-disclosure-testing -a codex`. Or copy the skill folder (agent/skills/info-disclosure-testing in NeoTheCapt/RedteamAgent) into .agents/skills/info-disclosure-testing in your project. Codex loads it when a task matches its description.

Can I use Info Disclosure Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NeoTheCapt/RedteamAgent --skill info-disclosure-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/info-disclosure-testing, .gemini/skills/info-disclosure-testing, .github/skills/info-disclosure-testing and .opencode/skills/info-disclosure-testing in your project.

What does Info Disclosure Testing need to run?

SKILL.md names no scripts, command-line tools or credentials: Info Disclosure Testing is instructions for the agent only.

Does Info Disclosure Testing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Info Disclosure Testing safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Info Disclosure Testing use?

No licence was found for Info Disclosure Testing or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Info Disclosure Testing use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Info Disclosure Testing?

Skills that share tags, products or a category with Info Disclosure Testing: Source Leak Hunt (uphiago/recon-skills, 1.3k stars), Code Audit (3stoneBrother/code-audit, 893 stars), Php Audit Pipeline (0xShe/PHP-Code-Audit-Skill, 402 stars) and Code Security Audit (ProgrammerAnthony/Expert-Coding-Harness, 235 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Info Disclosure Testing?

NeoTheCapt (a GitHub user) maintains it in NeoTheCapt/RedteamAgent, which has 142 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on August 2, 2026.

Source: NeoTheCapt/RedteamAgent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.