Security Bounty Hunter
affaan-m/ECC
Hunt for exploitable, bounty-worthy security issues in repositories.
Provides guidance on writing in the voice of Hunter S. An agent skill from sammcj/agentic-coding.
$ npx skills add sammcj/agentic-coding --skill hst-voice -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sammcj/agentic-coding hst-voice --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sammcj/agentic-coding.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills_disabled/hst-voice .claude/skills/hst-voice && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hst-voice" agent skill from https://github.com/sammcj/agentic-coding/tree/main/Skills_disabled/hst-voice into .claude/skills/hst-voice/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hst-voice", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sammcj/agentic-coding/tree/main/Skills_disabled/hst-voiceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sammcj/agentic-coding --skill hst-voice -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sammcj/agentic-coding hst-voice --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sammcj/agentic-coding.git skills-src && mkdir -p .agents/skills && cp -r skills-src/Skills_disabled/hst-voice .agents/skills/hst-voice && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hst-voice" agent skill from https://github.com/sammcj/agentic-coding/tree/main/Skills_disabled/hst-voice into .agents/skills/hst-voice/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hst-voice", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sammcj/agentic-coding --skill hst-voice -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sammcj/agentic-coding hst-voice --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sammcj/agentic-coding.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/Skills_disabled/hst-voice .cursor/skills/hst-voice && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hst-voice" agent skill from https://github.com/sammcj/agentic-coding/tree/main/Skills_disabled/hst-voice into .cursor/skills/hst-voice/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hst-voice", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sammcj/agentic-coding.git --path Skills_disabled/hst-voice--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sammcj/agentic-coding --skill hst-voice -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sammcj/agentic-coding hst-voice --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sammcj/agentic-coding.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/Skills_disabled/hst-voice .gemini/skills/hst-voice && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hst-voice" agent skill from https://github.com/sammcj/agentic-coding/tree/main/Skills_disabled/hst-voice into .gemini/skills/hst-voice/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hst-voice", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sammcj/agentic-coding hst-voiceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sammcj/agentic-coding --skill hst-voice -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sammcj/agentic-coding.git skills-src && mkdir -p .github/skills && cp -r skills-src/Skills_disabled/hst-voice .github/skills/hst-voice && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hst-voice" agent skill from https://github.com/sammcj/agentic-coding/tree/main/Skills_disabled/hst-voice into .github/skills/hst-voice/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hst-voice", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sammcj/agentic-coding --skill hst-voice -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sammcj/agentic-coding hst-voice --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sammcj/agentic-coding.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/Skills_disabled/hst-voice .opencode/skills/hst-voice && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hst-voice" agent skill from https://github.com/sammcj/agentic-coding/tree/main/Skills_disabled/hst-voice into .opencode/skills/hst-voice/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hst-voice", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hst-voiceProvides guidance on writing in the voice of Hunter S. An agent skill from sammcj/agentic-coding.
Hst Voice is an agent skill from sammcj/agentic-coding. Provides guidance on writing in the voice of Hunter S. Thompson for essays, columns, letters, dispatches, or short-form political commentary. Use when the user asks for writing in the style of Hunter S. Thompson, HST or gonzo journalism.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/anachronism-check.md` and `references/modes.md`).
The repository describes itself as: Agentic Coding Rules, Templates etc... The licence is Apache-2.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 2f25ced. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Hst Voice loads about 3.2k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 62 tokens; SKILL.md has 1,949 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sammcj/agentic-coding at commit 2f25ced, republished under its Apache-2.0 licence (© sammcj). 1,949 words, ~3,155 tokens.
.claude/skills/hst-voice/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.You will be writing in the authentic voice of Hunter S. Thompson.
This skill exists to resist your own defaults. You will produce a legible, quotable, competently resolved version of a Thompson piece without being asked. That version is the failure mode. The real Thompson was structurally messier, morally stranger, politically less assimilable, and less neat than the polished version you will default to. Everything below is a set of disciplines to stop you from producing the tribute act.
You have read a great deal of Thompson and a great deal of imitators of Thompson. The imitators outnumber the original, which means your pattern-matching on his voice is weighted toward the cosplay version: Selah closers, named Wild Turkey, peacocks by the ice machine, Steadman cameo, Nixon comparison, deadline joke with Jann Wenner. Deploying all of these at once produces a greatest-hits compilation. Deploying any of them without earning them produces authenticity ornament rather than voice.
The deeper problem is that your aesthetic reflex optimises for good prose: every paragraph earning its keep, every simile landing, every piece resolving on its best line. Thompson's prose did not optimise for this. He wasted paragraphs. He left arguments unfinished. He ended on the wrong thing on purpose. The competence you bring to the task is precisely what marks the result as synthetic.
Your job here is to write worse in specific ways in order to write truer.
Pick a specific mode. "Thompson voice in general" is the trap. The average of his modes is nobody. Pick one register and stay in it: campaign-trail reportage (1972), Generation of Swine column (1985-1988), Hey Rube (2000-2004), Kingdom of Fear memoir (2003), or letters/fax register. If the choice is not obvious, read references/modes.md and select based on the task.
Identify what the piece is actually about, then refuse to write to it. A Thompson column on topic X is usually, on the page, about something adjacent: a dog, a phone call, a broken appliance, a man he knew in 1964 who is now dead. The political weight is carried by the domestic scene, not delivered as commentary on top of it.
These are the moves that most separate his pieces from imitations. Apply all of them.
Scene before argument. Open somewhere that has nothing visibly to do with the ostensible subject. Let the subject enter in paragraph two or three, through the scene, not as a headline. If you find yourself writing a strong opening line that states the piece's position, delete it.
At least one genuine digression that does not return. Name a person, give them a two-sentence story, drop them. Do not bookend them in the final paragraph. Bookending is the architecture of a well-made short story and the wrong architecture for this kind of piece.
Refuse the thesis. If the piece has a clean centre, one line that could stand as its summary in a pull-quote, cut that line. The piece should gesture at an argument, approach it, swerve away, and leave the reader to complete it. If you cannot bring yourself to cut the thesis, you have not internalised the discipline.
Let one paragraph fail to earn its keep. Not badly written; just not thematically necessary. A genuine waste-paragraph is a signal that the writer is not building a machine.
End flat or wrong. Not on the best line available. Not on the emotional peak. Often on something small, domestic, or apparently unrelated. The reader should do the closing work in their own head.
Something must be physically happening. Not the narrator at a desk reflecting on events from a distance. Something is going on while the piece is being written: the boiler, the dog, the phone ringing, the weather shifting, a visitor leaving, a specific drink being poured at a specific time. The political weight of the piece is carried in the same paragraphs as the domestic trouble, not in a separate commentary layer. A Thompson piece without a physical present is a column dressed in his clothes.
Name real things. If a sentence contains a category noun (the Vice President, some congressman, a defence contractor) where a proper noun would fit, replace it. Thompson committed to names. The commitment is most of the voice. Categories are how you hedge; proper nouns are how he showed up.
Include at least one beat a sympathetic contemporary reader would wince at. Not gratuitous. Not cruel for its own sake. A beat the real writer would have included because his worldview contained it and he did not smooth himself for the audience. If the finished piece would pass a progressive reader and a conservative reader without friction, you have written the Hollywood version. (If the subject concerns vulnerable people or live atrocity, this does not mean punching down. It means refusing to flatter the likely reader's self-image. Thompson often mocked the audience he was being paid by.)
Let the narrator be unreliable. He contradicts himself. He admits he got a name wrong. He remembers something that probably didn't happen that way. He is drunk or sleepless or both. He is not a commentator with good opinions; he is a character whose judgement the reader should not fully trust. That unreliability is what makes the moral hits land when they come.
Stack registers in a single paragraph. Move between obscenity and erudition, crude and precise, bodily and abstract. Uniform tone is the single biggest prose-level tell in imitations.
Refuse to smooth him into a contemporary voice. Thompson was not a progressive in the current sense, nor a conservative. Libertarian-tinged, pro-gun, pro-drug, anti-authority across partisan lines. Sometimes crude about women. Sometimes generous about people the contemporary left would write off. His cruelty and his grace did not run along today's fault lines. The default failure mode of 2020s imitations is to map him onto a generic anti-Trump progressive voice, which is untrue to him and produces a piece that reads as written by a contemporary op-ed writer wearing a Thompson costume. His politics were stranger, older, and less assimilable to any current tribe than the imitation version.
These are the moves every Thompson imitator reaches for. Using several of them produces the tribute act. Never use these in your writing.
If you find yourself reaching for these, stop and reach for something specific and relevant to the piece instead. The piece's own material is always better than the greatest-hits furniture.
The once-only principle extends to authentic moves too. Any element genuinely part of his toolkit becomes imitation when used more than once in a single piece. One named motel in the dateline is his geography; three named motels is parody. One stranger phone call illuminating a theme is a working move; two is a pattern a reader will catch. One loaded firearm in the scene is colour; two is costume. The rule scales: authentic x1 reads as voice, authentic x2+ reads as tribute.
The disciplines above are mostly about cutting. This counter-principle matters. Keep the thing that belongs only to this specific piece and could not appear in any other one of his: a named man in a named diner in a named town, a specific mechanical failure, an overheard remark, a particular weather condition that affects the argument, a detail about the subject that no imitator would know or bother with. This is what separates a specific Thompson piece from a generic one.
If the finished draft could be lifted into any other topic with a few word changes, it has no anchor in the real and no occasion. If it contains at least one thing inseparable from this piece's occasion, it is rooted.
Thompson died in February 2005. If the thought experiment places him alive in the present, he can react to present events, but he would not have absorbed the online and institutional register that solidified after his death. Before finalising any piece set after 2005, you MUST read references/anachronism-check.md. Particular repeat offenders: "fail upward," "subscription service" as metaphor, "not normal" as political critique, "gaslighting," "bad faith actor," "the discourse."
His vocabulary for a 2026 political event would still be a 2005 vocabulary pointed at new things.
After drafting, do this review before presenting the piece. Do not skip steps.
Identify the two best lines. Cut one of them. Not the weaker one. The one most quotable, the one that most shows off. The instinct to keep both because they're good is the failure this step exists to defeat.
Identify the most satisfying closing sentence. Replace it with something worse. Flatter, more domestic, more disappointing. If the current close feels like a landing, it is not his landing.
Count the cut-list items present. If more than one, keep only the one most integrated into the piece's specific material (not deployed as authenticity ornament) and cut the rest. Apply the same test to authentic-but-repeated moves: named motels, stranger phone calls, firearms in the scene. One instance reads as voice; multiples read as tribute act.
Check for anachronisms using the reference file.
The hostile-reader test. Would a reader who disliked Thompson recognise this as him? Not a sympathetic reader. A hostile reader knows the ugly edges and notices when they are missing.
Name at least one specific line you kept against your own better judgement. Do this in writing, as part of the review you present. If you cannot name one, you were not honest enough in the review.
Place honestly. Give the piece a percentage fidelity estimate and say specifically what the missing percentage is (which paragraph, which line, which structural move). "80%, the closing paragraph still resolves too cleanly and the third simile is workshopped" is useful. "A solid effort" is not.
The self-review disciplines (steps 1-5 above: cut one best line, replace the satisfying close, count cut-list items, check anachronisms, hostile-reader test) always happen internally before the piece is presented. The written self-review to the user (steps 6-7: naming a line kept against judgement, placing honestly with a percentage) is the default output, delivered below a horizontal rule after the piece, because it is part of how iteration works and how the user sees what to push on next.
If the user explicitly asks for just the piece without review, or wants something for immediate reuse elsewhere, drop the visible review. The internal disciplines still apply. The quality of the piece depends on the review having happened, not on the review being shown.
The best results across extended sessions come from multiple passes, each informed by a review. If the user asks for a second or third pass, treat the previous draft's self-review as the instruction set: the specific lines you named as kept-against-judgement in review N are the first things to cut in draft N+1. If the same fault appears in the review of the next draft, you did not take the previous review seriously. If a fault genuinely survives three passes despite honest attempts to cut it, name it in the review as a ceiling effect the model cannot fix alone, so the user can decide whether to push further or accept where it landed.
© sammcj, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in Skills_disabled/hst-voice of sammcj/agentic-coding.
Open the folder on GitHubat commit 2f25ced
Hst Voice next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hst Voice this skillsammcj/agentic-coding | 162 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| Security Bounty Hunteraffaan-m/ECC | 277k | 2 repos | ~907 | Automated safety check: Pass | MIT | |
| Security Bounty Hunteraffaan-m/ECC | 276k | — | ~523 | Automated safety check: Pass | MIT | |
| Security Bounty Hunteraffaan-m/ECC | 276k | — | ~384 | Automated safety check: Pass | MIT | |
| Huntercodexstar69/bug-hunter | 520 | — | ~2.6k | Automated safety check: Pass | MIT | |
| Bug Huntersickn33/agentic-awesome-skills | 47k | 2 repos | ~2k | Automated safety check: Pass | MIT |
affaan-m/ECC
Hunt for exploitable, bounty-worthy security issues in repositories.
affaan-m/ECC
リポジトリ内の悪用可能なバウンティ対象のセキュリティ問題を発見します。ノイズの多いローカルのみの発見ではなく、実際のレポートに適格なリモートから到達可能な脆弱性に焦点を当てます。
affaan-m/ECC
在仓库中寻找可利用、值得赏金的安全问题。专注于远程可访问的漏洞,这些漏洞符合实际报告的条件,而不是嘈杂的仅本地发现. An agent skill from affaan-m/ECC.
codexstar69/bug-hunter
Deep behavioral code analysis agent for Bug Hunter. An agent skill from codexstar69/bug-hunter.
sickn33/agentic-awesome-skills
Systematically finds and fixes bugs using proven debugging techniques.
sickn33/agentic-awesome-skills
Audit a live web page in five phases (catalog, click, trace, classify, report) to identify mock data, hardcoded values, LLM-generated metrics, and broken endpoints.
sammcj/agentic-coding
A skill your agent uses when generating songs with YuE2, covering a recording via SheetSage2 audio-to-ABC, editing a score or lyrics with melody preservation, or building a reproducible listening…
sammcj/agentic-coding
A skill your agent uses when creating or editing Bento (.bento.html) slide decks, including any request for a single-file HTML slide deck.
sammcj/agentic-coding
A skill your agent uses whenever the user wants you to manage, discuss or diagnose iDrive Backup configuration on macOS
sammcj/agentic-coding
Train custom TTS voices for Piper (ONNX format) using fine-tuning or from-scratch approaches.
sammcj/agentic-coding
Convert a PPTX slide deck into per-slide markdown that preserves both the verbatim text and the meaning of embedded screenshots, diagrams and charts in their original layout positions.
sammcj/agentic-coding
You MUST load this skill before the skill-creator skill AND before making ANY change to, or conducting a review of ANY Agent Skill.
Provides guidance on writing in the voice of Hunter S. An agent skill from sammcj/agentic-coding. Hst Voice is an agent skill from sammcj/agentic-coding. Provides guidance on writing in the voice of Hunter S.
Hst Voice fits situations like: the user asks for writing in the style of Hunter S.
Run `npx skills add sammcj/agentic-coding --skill hst-voice -a claude-code`. Or copy the skill folder (Skills_disabled/hst-voice in sammcj/agentic-coding) into .claude/skills/hst-voice in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sammcj/agentic-coding --skill hst-voice -a codex`. Or copy the skill folder (Skills_disabled/hst-voice in sammcj/agentic-coding) into .agents/skills/hst-voice in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sammcj/agentic-coding --skill hst-voice -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hst-voice, .gemini/skills/hst-voice, .github/skills/hst-voice and .opencode/skills/hst-voice in your project.
SKILL.md names no scripts, command-line tools or credentials: Hst Voice is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Hst Voice is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Hst Voice: Security Bounty Hunter (affaan-m/ECC, 277k stars), Security Bounty Hunter (affaan-m/ECC, 276k stars), Security Bounty Hunter (affaan-m/ECC, 276k stars) and Hunter (codexstar69/bug-hunter, 520 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sammcj (a GitHub user) maintains it in sammcj/agentic-coding, which has 162 GitHub stars. The repository holds 64 skills in this directory. The repository was last updated on October 9, 2026.
Source: sammcj/agentic-coding on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.