Data Table Manager
n8n-io/n8n
Load before calling data-tables or parse-file. An agent skill from n8n-io/n8n.
Detect and investigate bulk registration abuse on SaaS platforms.
$ npx skills add nexu-io/harness-engineering-guide --skill abuse-hunter -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nexu-io/harness-engineering-guide abuse-hunter --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nexu-io/harness-engineering-guide.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/abuse-hunter .claude/skills/abuse-hunter && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "abuse-hunter" agent skill from https://github.com/nexu-io/harness-engineering-guide/tree/main/skills/abuse-hunter into .claude/skills/abuse-hunter/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "abuse-hunter", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nexu-io/harness-engineering-guide/tree/main/skills/abuse-hunterType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nexu-io/harness-engineering-guide --skill abuse-hunter -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nexu-io/harness-engineering-guide abuse-hunter --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nexu-io/harness-engineering-guide.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/abuse-hunter .agents/skills/abuse-hunter && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "abuse-hunter" agent skill from https://github.com/nexu-io/harness-engineering-guide/tree/main/skills/abuse-hunter into .agents/skills/abuse-hunter/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "abuse-hunter", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nexu-io/harness-engineering-guide --skill abuse-hunter -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nexu-io/harness-engineering-guide abuse-hunter --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nexu-io/harness-engineering-guide.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/abuse-hunter .cursor/skills/abuse-hunter && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "abuse-hunter" agent skill from https://github.com/nexu-io/harness-engineering-guide/tree/main/skills/abuse-hunter into .cursor/skills/abuse-hunter/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "abuse-hunter", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nexu-io/harness-engineering-guide.git --path skills/abuse-hunter--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nexu-io/harness-engineering-guide --skill abuse-hunter -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nexu-io/harness-engineering-guide abuse-hunter --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nexu-io/harness-engineering-guide.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/abuse-hunter .gemini/skills/abuse-hunter && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "abuse-hunter" agent skill from https://github.com/nexu-io/harness-engineering-guide/tree/main/skills/abuse-hunter into .gemini/skills/abuse-hunter/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "abuse-hunter", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nexu-io/harness-engineering-guide abuse-hunterInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nexu-io/harness-engineering-guide --skill abuse-hunter -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nexu-io/harness-engineering-guide.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/abuse-hunter .github/skills/abuse-hunter && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "abuse-hunter" agent skill from https://github.com/nexu-io/harness-engineering-guide/tree/main/skills/abuse-hunter into .github/skills/abuse-hunter/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "abuse-hunter", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nexu-io/harness-engineering-guide --skill abuse-hunter -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nexu-io/harness-engineering-guide abuse-hunter --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nexu-io/harness-engineering-guide.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/abuse-hunter .opencode/skills/abuse-hunter && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "abuse-hunter" agent skill from https://github.com/nexu-io/harness-engineering-guide/tree/main/skills/abuse-hunter into .opencode/skills/abuse-hunter/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "abuse-hunter", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
abuse-hunterDetect and investigate bulk registration abuse on SaaS platforms.
Abuse Hunter is an agent skill from nexu-io/harness-engineering-guide. Detect and investigate bulk registration abuse on SaaS platforms. Given access to a user database (or exported CSV/JSON), run a multi-dimensional anomaly analysis — email domain clustering, registration tempo, UA fingerprinting, session structure, usage patterns, and credit consumption — to produce a scored abuse report with actionable recommendations. Use when investigating suspicious sign-up spikes, credit fraud, free-tier abuse, or account farming.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/analyze.py`).
It sits in Documents & Office, covering CSV and tabular files. The repository describes itself as: 🔧 The open guide to Harness Engineering — concepts, tutorials, papers, tools, and resources for building and managing AI agent runtimes. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 86fec9b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
curljqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.vvhan.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Abuse Hunter loads about 1.9k tokens when it runs. Until then it costs about 117 tokens; SKILL.md has 231 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from nexu-io/harness-engineering-guide at commit 86fec9b, republished under its MIT licence (© nexu-io). 231 words, ~1,888 tokens.
.claude/skills/abuse-hunter/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.一键排查你的 SaaS 平台是否存在批量注册、薅免费额度、账号农场等滥用行为。
按顺序执行,每一步都会输出中间结论,最终汇总为综合评分。
目标:找出注册量异常高的邮箱域名
-- 按邮箱域名统计注册用户数,找出 Top 异常域名
SELECT
SUBSTRING(email FROM '@(.+)$') AS domain,
COUNT(*) AS user_count,
MIN(created_at) AS first_signup,
MAX(created_at) AS last_signup,
EXTRACT(EPOCH FROM MAX(created_at) - MIN(created_at)) / 3600 AS span_hours
FROM users
GROUP BY domain
HAVING COUNT(*) > 10
ORDER BY user_count DESC
LIMIT 20;判定标准:
域名背景检查:
# WHOIS 查域名创建时间和注册商
whois <domain> | grep -iE "creation|registrar|name server"
# DNS 检查:有没有网站,有没有邮件配置
dig <domain> MX +short
dig <domain> A +short
# 是否有 ICP 备案(仅中国域名)
curl -s "https://api.vvhan.com/api/icp?url=<domain>" | jq .目标:判断注册节奏是自然增长还是批量注入
-- 按天统计注册量(可疑域名)
SELECT
DATE(created_at) AS reg_date,
COUNT(*) AS daily_count
FROM users
WHERE email LIKE '%@<suspect_domain>'
GROUP BY reg_date
ORDER BY reg_date;
-- 按小时统计(找注册高峰)
SELECT
DATE(created_at) AS reg_date,
EXTRACT(HOUR FROM created_at) AS reg_hour,
COUNT(*) AS hourly_count
FROM users
WHERE email LIKE '%@<suspect_domain>'
GROUP BY reg_date, reg_hour
HAVING COUNT(*) > 10
ORDER BY hourly_count DESC;
-- 注册间隔分析(关键!)
WITH ordered AS (
SELECT created_at,
LAG(created_at) OVER (ORDER BY created_at) AS prev_at
FROM users
WHERE email LIKE '%@<suspect_domain>'
)
SELECT
PERCENTILE_CONT(0.5) WITHIN GROUP (ORDER BY EXTRACT(EPOCH FROM created_at - prev_at)) AS median_interval_sec,
PERCENTILE_CONT(0.9) WITHIN GROUP (ORDER BY EXTRACT(EPOCH FROM created_at - prev_at)) AS p90_interval_sec
FROM ordered
WHERE prev_at IS NOT NULL;判定标准:
阶段切换检测: 将注册按时间分段,检查是否存在"前期小量试探 + 后期大量涌入"模式。如果存在,说明攻击者经历了"测试→放量"的阶段。
目标:判断邮箱地址是人工创建还是程序生成
-- 前缀长度分布
SELECT
LENGTH(SPLIT_PART(email, '@', 1)) AS prefix_len,
COUNT(*) AS cnt
FROM users
WHERE email LIKE '%@<suspect_domain>'
GROUP BY prefix_len
ORDER BY cnt DESC;
-- 前缀字符模式分类
SELECT
CASE
WHEN SPLIT_PART(email, '@', 1) ~ '^[a-z]+$' THEN 'letters_only'
WHEN SPLIT_PART(email, '@', 1) ~ '^[0-9]+$' THEN 'digits_only'
WHEN SPLIT_PART(email, '@', 1) ~ '^[a-z0-9]{6}$' THEN '6char_alnum'
WHEN SPLIT_PART(email, '@', 1) ~ '^[a-z0-9]{5}$' THEN '5char_alnum'
ELSE 'other'
END AS prefix_pattern,
COUNT(*) AS cnt
FROM users
WHERE email LIKE '%@<suspect_domain>'
GROUP BY prefix_pattern
ORDER BY cnt DESC;判定标准:
目标:判断注册环境的多样性
-- UA 丰富度对比(可疑域名 vs 全量用户)
-- 可疑域名
SELECT
COUNT(DISTINCT session_id) AS total_sessions,
COUNT(DISTINCT user_agent) AS unique_uas,
ROUND(COUNT(DISTINCT user_agent)::NUMERIC / NULLIF(COUNT(DISTINCT session_id), 0), 4) AS ua_diversity
FROM sessions s
JOIN users u ON s.user_id = u.id
WHERE u.email LIKE '%@<suspect_domain>';
-- 全量用户(基线)
SELECT
COUNT(DISTINCT session_id) AS total_sessions,
COUNT(DISTINCT user_agent) AS unique_uas,
ROUND(COUNT(DISTINCT user_agent)::NUMERIC / NULLIF(COUNT(DISTINCT session_id), 0), 4) AS ua_diversity
FROM sessions s
JOIN users u ON s.user_id = u.id
WHERE u.email NOT LIKE '%@<suspect_domain>';
-- 每用户 session 数分布
SELECT
u.email LIKE '%@<suspect_domain>' AS is_suspect,
PERCENTILE_CONT(0.5) WITHIN GROUP (ORDER BY session_count) AS median_sessions,
PERCENTILE_CONT(0.9) WITHIN GROUP (ORDER BY session_count) AS p90_sessions
FROM (
SELECT user_id, COUNT(*) AS session_count
FROM sessions GROUP BY user_id
) sc
JOIN users u ON sc.user_id = u.id
GROUP BY is_suspect;判定标准:
目标:判断账号是"注册即用"还是"先备号再启用"
-- 注册到首次使用的间隔
SELECT
u.email LIKE '%@<suspect_domain>' AS is_suspect,
COUNT(*) AS users_with_usage,
PERCENTILE_CONT(0.5) WITHIN GROUP (
ORDER BY EXTRACT(EPOCH FROM first_usage - u.created_at)
) AS median_activation_sec,
PERCENTILE_CONT(0.9) WITHIN GROUP (
ORDER BY EXTRACT(EPOCH FROM first_usage - u.created_at)
) AS p90_activation_sec
FROM users u
JOIN (
SELECT user_id, MIN(created_at) AS first_usage
FROM usage_events GROUP BY user_id
) ue ON u.id = ue.user_id
GROUP BY is_suspect;
-- 使用覆盖率
SELECT
u.email LIKE '%@<suspect_domain>' AS is_suspect,
COUNT(*) AS total_users,
COUNT(ue.user_id) AS users_with_usage,
ROUND(COUNT(ue.user_id)::NUMERIC / COUNT(*), 4) AS usage_rate
FROM users u
LEFT JOIN (
SELECT DISTINCT user_id FROM usage_events
) ue ON u.id = ue.user_id
GROUP BY is_suspect;判定标准:
目标:量化实际经济损失
-- 可疑域名积分消耗汇总
SELECT
COUNT(*) AS accounts_with_credits,
SUM(total_granted) AS total_credits_granted,
SUM(total_consumed) AS total_credits_consumed,
SUM(total_expired) AS total_credits_expired,
ROUND(SUM(total_consumed)::NUMERIC / NULLIF(SUM(total_granted), 0), 4) AS consumption_rate
FROM credit_summary cs
JOIN users u ON cs.user_id = u.id
WHERE u.email LIKE '%@<suspect_domain>';
-- 模型调用成本 Top 10
SELECT
model_name,
COUNT(*) AS call_count,
COUNT(DISTINCT user_id) AS unique_users,
ROUND(SUM(cost_usd)::NUMERIC, 2) AS total_cost
FROM usage_events ue
JOIN users u ON ue.user_id = u.id
WHERE u.email LIKE '%@<suspect_domain>'
GROUP BY model_name
ORDER BY total_cost DESC
LIMIT 10;每个维度 0-2 分,总分 12 分:
| 维度 | 0 分(正常) | 1 分(可疑) | 2 分(高风险) |
|---|---|---|---|
| 域名聚类 | <50 注册 | 50-100 注册 | >100 注册 |
| 注册节奏 | 间隔 >5min | 间隔 1-5min | 间隔 <1min |
| 前缀模式 | 自然分布 | 部分规律 | >80% 固定模式 |
| UA 指纹 | 丰富度正常 | 偏低 | 低一个数量级 |
| 激活时间 | 正常 | 偏慢 | 明显先备后用 |
| 积分消耗 | 低消耗 | 中等 | 大规模薅取 |
总分判定:
排查完成后输出结构化报告:
# 滥用排查报告
## 目标域名:xxx.yyy
## 排查时间:YYYY-MM-DD
## 综合评分:X / 12(✅ / ⚠️ / 🚨)
### 各维度评分
| 维度 | 得分 | 关键发现 |
|------|------|---------|
| ... | ... | ... |
### 关键时间线
- Day 1: ...
- Day N: ...
### 影响评估
- 涉及账号数:
- 消耗积分:
- 推理成本:
### 处置建议
1. 即时:...
2. 短期:...
3. 长期:...根据评分自动推荐:
以上 SQL 基于 PostgreSQL 语法。如果你的数据库是:
SUBSTRING(... FROM ...) 改为 SUBSTRING_INDEX(),PERCENTILE_CONT 需要用子查询模拟$group, $match, $project)scripts/analyze.py如果表名或字段名不同,告诉我你的 schema,我会自动适配查询。
© nexu-io, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (scripts) in skills/abuse-hunter of nexu-io/harness-engineering-guide.
Open the folder on GitHubat commit 86fec9b
Abuse Hunter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Abuse Hunter this skillnexu-io/harness-engineering-guide | 664 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Data Table Managern8n-io/n8n | 207k | — | ~2.3k | Automated safety check: Pass | Custom licence | |
| Instrument Data To Allotropeaws-samples/amazon-bedrock-agents-healthcare-lifesciences | 274 | 2 repos | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Intelligence Requirements BuilderTracecatHQ/tracecat | 3.8k | — | ~6k | Automated safety check: Pass | MIT | |
| Markitshift-labs-ai/markit | 1.3k | — | ~299 | Automated safety check: Pass | MIT | |
| Sector Analysttradermonty/claude-trading-skills | 3k | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
n8n-io/n8n
Load before calling data-tables or parse-file. An agent skill from n8n-io/n8n.
aws-samples/amazon-bedrock-agents-healthcare-lifesciences
Convert laboratory instrument output files (PDF, CSV, Excel, TXT) to Allotrope Simple Model (ASM) JSON format or flattened 2D CSV.
TracecatHQ/tracecat
Turns a vague, high-level stakeholder ask into a structured set of intelligence requirements for a CTI team, complete with Essential Elements of Information, collection guidance, success criteria…
shift-labs-ai/markit
Convert files and URLs to Markdown. An agent skill from shift-labs-ai/markit.
tradermonty/claude-trading-skills
This skill should be used when analyzing sector rotation patterns and market cycle positioning.
ckpxgfnksd-max/uap-release-analyzer
Inventory, extract, and analyze tranches of declassified UAP/UFO files — including war.gov/UFO/ "PURSUE" releases, FBI Vault, NARA boxes, and AARO publications.
Categories
Detect and investigate bulk registration abuse on SaaS platforms. Abuse Hunter is an agent skill from nexu-io/harness-engineering-guide. Detect and investigate bulk registration abuse on SaaS platforms.
Abuse Hunter fits situations like: investigating suspicious sign-up spikes; free-tier abuse; account farming.
Run `npx skills add nexu-io/harness-engineering-guide --skill abuse-hunter -a claude-code`. Or copy the skill folder (skills/abuse-hunter in nexu-io/harness-engineering-guide) into .claude/skills/abuse-hunter in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nexu-io/harness-engineering-guide --skill abuse-hunter -a codex`. Or copy the skill folder (skills/abuse-hunter in nexu-io/harness-engineering-guide) into .agents/skills/abuse-hunter in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nexu-io/harness-engineering-guide --skill abuse-hunter -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/abuse-hunter, .gemini/skills/abuse-hunter, .github/skills/abuse-hunter and .opencode/skills/abuse-hunter in your project.
Going by SKILL.md and its folder, Abuse Hunter needs Python for the scripts in its folder and the command-line tools its instructions call (curl and jq). Our summary lists: Python 3.
SKILL.md names 1 domain. In commands or code: api.vvhan.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Abuse Hunter is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Abuse Hunter: Data Table Manager (n8n-io/n8n, 207k stars), Instrument Data To Allotrope (aws-samples/amazon-bedrock-agents-healthcare-lifesciences, 274 stars), Intelligence Requirements Builder (TracecatHQ/tracecat, 3.8k stars) and Markit (shift-labs-ai/markit, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nexu-io (a GitHub organization) maintains it in nexu-io/harness-engineering-guide, which has 664 GitHub stars. The repository was last updated on April 19, 2026.
Source: nexu-io/harness-engineering-guide on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.