Agent skill

Vulnhunter

by sendaifun in sendaifun/skills

Security vulnerability detection and variant analysis skill.

Apache-2.0Auto-check passedSecurity

Install Vulnhunter

skills CLI
$ npx skills add sendaifun/skills --skill vulnhunter -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sendaifun/skills vulnhunter --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sendaifun/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vulnhunter .claude/skills/vulnhunter && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vulnhunter
GitHub stars
130
Used in
1 other repo
Token cost
~2.3k tokens
SKILL.md length
502 words
Files
7
Skills in repo
24
Repo updated
First seen
Licence
Apache-2.0

At a glance

Security vulnerability detection and variant analysis skill.

  • Works in 3 steps: Dangerous Default Configurations → Error-Prone APIs → Language-Specific Footguns
  • Hunting for dangerous APIs
  • SKILL.md covers Overview, Sharp Edges Detection, Variant Analysis and Workflow, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Vulnhunter is an agent skill from sendaifun/skills. Security vulnerability detection and variant analysis skill. Use when hunting for dangerous APIs, footgun patterns, error-prone configurations, and vulnerability variants across codebases. Combines sharp edges detection with variant hunting methodology.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files (for example `docs/methodology.md`, `examples/smart-contracts/reentrancy-hunt.md` and `examples/web-apps/sql-injection-hunt.md`).

It sits in Security, covering Static analysis and SAST. The repository describes itself as: a public marketplace of all solana-related skills for agents to learn from! The licence is Apache-2.0.

When your agent uses it

  • Hunting for dangerous APIs
  • Footgun patterns
  • Error-prone configurations
  • Vulnerability variants across codebases

Example prompts

  • “/vulnhunter”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Dangerous Default Configurations
  2. Error-Prone APIs
  3. Language-Specific Footguns

What it can do on your machine

Read from SKILL.md and the folder at commit 06b36b8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are c, javascript, python, rust, solidity, bash, markdown, yaml and ql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vulnhunter loads about 2.3k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 502 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sendaifun/skills at commit 06b36b8, republished under its Apache-2.0 licence (© sendaifun). 502 words, ~2,277 tokens.

Download SKILL.mdSave it as .claude/skills/vulnhunter/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
vulnhunter
description
Security vulnerability detection and variant analysis skill. Use when hunting for dangerous APIs, footgun patterns, error-prone configurations, and vulnerability variants across codebases. Combines sharp edges detection with variant hunting methodology.

VulnHunter - Security Vulnerability Detection & Analysis

A comprehensive security audit skill for identifying dangerous APIs, footgun patterns, error-prone configurations, and hunting for vulnerability variants across codebases. Inspired by Trail of Bits' sharp-edges and variant-analysis methodologies.

Overview

VulnHunter combines two powerful security analysis techniques:

  1. Sharp Edges Detection - Identify error-prone APIs, dangerous defaults, and footgun designs
  2. Variant Analysis - Find similar vulnerabilities across codebases using pattern-based analysis
When to Use VulnHunter

Activate this skill when:

  • Conducting security code reviews or audits
  • Reviewing third-party dependencies for dangerous patterns
  • Hunting for variants of known vulnerabilities
  • Assessing API design for security footguns
  • Pre-audit reconnaissance of unfamiliar codebases

Sharp Edges Detection

Categories of Sharp Edges
1. Dangerous Default Configurations

Look for configurations that are insecure by default:

- CORS: Access-Control-Allow-Origin: *
- Debug modes enabled in production
- Default credentials or API keys
- Permissive file permissions (777, 666)
- SSL/TLS verification disabled
- Insecure deserialization settings
2. Error-Prone APIs

Memory Safety:

c
// Dangerous: No bounds checking
strcpy(), strcat(), sprintf(), gets()
memcpy() without size validation

// Safer alternatives
strncpy(), strncat(), snprintf(), fgets()
memcpy_s() with explicit size

Cryptography Footguns:

- ECB mode encryption
- MD5/SHA1 for security purposes
- Hardcoded IVs or salts
- Custom crypto implementations
- Random without CSPRNG (Math.random for tokens)

Concurrency Issues:

- Race conditions in file operations
- Time-of-check to time-of-use (TOCTOU)
- Double-checked locking anti-patterns
- Non-atomic increment/decrement operations
3. Language-Specific Footguns

JavaScript/TypeScript:

javascript
// Dangerous patterns
eval(), new Function(), setTimeout(string)
innerHTML, outerHTML, document.write()
Object.assign() for deep clone (shallow only!)
== instead of === (type coercion)

Python:

python
# Dangerous patterns
pickle.loads(untrusted)  # RCE vector
yaml.load(untrusted)     # Use safe_load
exec(), eval()
os.system(), subprocess with shell=True

Rust:

rust
// Patterns requiring extra scrutiny
unsafe { }
.unwrap() in production code
mem::transmute()
raw pointer dereference

Solidity/Smart Contracts:

solidity
// High-risk patterns
tx.origin for authentication  // Phishing vulnerable
delegatecall to untrusted     // Storage collision
selfdestruct                  // Permanent destruction
block.timestamp for randomness // Miner manipulable
Sharp Edges Checklist

When reviewing code, systematically check for:

  • Authentication bypasses - Missing auth checks, default credentials
  • Authorization flaws - Privilege escalation, IDOR patterns
  • Injection vectors - SQL, Command, Template, XSS
  • Cryptographic weaknesses - Weak algorithms, improper key handling
  • Resource exhaustion - Unbounded loops, memory allocation
  • Race conditions - TOCTOU, concurrent state modification
  • Information disclosure - Verbose errors, debug endpoints
  • Deserialization - Untrusted data unmarshaling
  • Path traversal - User-controlled file paths
  • SSRF vectors - User-controlled URLs, redirects

Variant Analysis

The Variant Hunting Process
  1. Identify the Root Cause - Understand WHY a vulnerability exists
  2. Extract the Pattern - What code structure enables it?
  3. Generalize the Pattern - Create regex/AST patterns
  4. Search Codebase - Hunt for similar structures
  5. Validate Findings - Confirm each variant is exploitable
Pattern Extraction Templates
Template 1: Missing Validation Pattern
Original bug: User input flows to SQL query without sanitization
Pattern: [user_input] -> [sink_function] without [validation_function]

Search for:
- Direct database calls with string concatenation
- ORM raw query methods with user parameters
- Similar data flows in adjacent modules
Template 2: Authentication Bypass
Original bug: Endpoint missing auth middleware
Pattern: Route definition without auth decorator/middleware

Search for:
- Routes defined after the vulnerable one
- Similar API patterns in other modules
- Admin/internal endpoints
Template 3: Race Condition
Original bug: Check-then-act without atomicity
Pattern: if (check_condition()) { act_on_condition() }

Search for:
- File existence checks followed by file operations
- Permission checks followed by privileged actions
- Balance checks followed by transfers
Search Strategies
bash
# Find potential SQL injection
grep -rn "execute.*%s" --include="*.py"
grep -rn "query.*\+" --include="*.js"

# Find dangerous deserialize
grep -rn "pickle.loads\|yaml.load\|eval(" --include="*.py"

# Find command injection vectors
grep -rn "os.system\|subprocess.*shell=True" --include="*.py"
Semantic Search (AST-Based)

For more precise matching, use AST-based tools:

  • Semgrep - Cross-language semantic grep
  • CodeQL - GitHub's semantic analysis
  • tree-sitter - Universal parser
Variant Analysis Report Template
markdown
## Variant Analysis Report

### Original Finding
- **ID**: FINDING-001
- **Severity**: High
- **Root Cause**: [Description]
- **Affected File**: path/to/file.ext:line

### Pattern Extracted
[Code pattern or regex]

### Variants Discovered

| # | Location | Severity | Status | Notes |
|---|----------|----------|--------|-------|
| 1 | file.ext:42 | High | Confirmed | Same root cause |
| 2 | other.ext:100 | Medium | Suspected | Needs validation |

### Recommendations
[Systematic fix approach]

Workflow

Show full SKILL.md (204 more words)Show less
Phase 1: Reconnaissance
  1. Identify technology stack and languages
  2. Map entry points (APIs, CLI, file inputs)
  3. Locate authentication/authorization logic
  4. Find cryptographic operations
  5. Identify external integrations
Phase 2: Sharp Edges Scan
  1. Run through sharp edges checklist
  2. Focus on security-critical paths
  3. Document all suspicious patterns
  4. Cross-reference with known CVEs
Phase 3: Variant Hunting
  1. For each finding, extract pattern
  2. Search for variants systematically
  3. Validate each potential variant
  4. Assess aggregate risk
Phase 4: Reporting
  1. Consolidate findings by category
  2. Assign severity ratings
  3. Provide remediation guidance
  4. Highlight systemic issues

Integration with Static Analysis

Semgrep Rules for Common Patterns
yaml
# Example: Detect SQL injection in Python
rules:
  - id: sql-injection-format
    patterns:
      - pattern: $CURSOR.execute($QUERY % ...)
    message: "Potential SQL injection via string formatting"
    severity: ERROR
    languages: [python]
CodeQL Queries
ql
// Find tainted data flowing to dangerous sinks
import python
import semmle.python.dataflow.TaintTracking

from DataFlow::PathNode source, DataFlow::PathNode sink
where TaintTracking::localTaint(source.getNode(), sink.getNode())
  and sink.getNode().asExpr().(Call).getTarget().getName() = "execute"
select sink, source, sink, "Tainted input reaches SQL execution"

Examples

See the /examples folder for:

  • Real-world sharp edges examples by language
  • Variant analysis case studies
  • Pattern extraction walkthroughs

Resources

  • resources/sharp-edges-catalog.md - Comprehensive catalog of dangerous patterns
  • resources/variant-patterns.md - Common vulnerability pattern templates
  • templates/variant-report.md - Report template for variant analysis

Guidelines

  1. Always verify - Don't report theoretical issues as confirmed vulnerabilities
  2. Context matters - A pattern may be safe in one context, dangerous in another
  3. Prioritize exploitability - Focus on patterns that lead to real impact
  4. Document assumptions - Note any threat model assumptions
  5. Systemic over point fixes - Recommend architectural improvements when patterns repeat

Skill Files

vulnhunter/
├── SKILL.md                          # This file
├── resources/
│   ├── sharp-edges-catalog.md        # Categorized dangerous patterns
│   └── variant-patterns.md           # Vulnerability pattern templates
├── examples/
│   ├── smart-contracts/              # Solidity/blockchain examples
│   ├── web-apps/                     # Web application examples
│   └── native-code/                  # C/C++/Rust examples
├── templates/
│   └── variant-report.md             # Analysis report template
└── docs/
    └── methodology.md                # Detailed methodology guide

© sendaifun, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files in skills/vulnhunter of sendaifun/skills.

  • SKILL.md
  • docs/methodology.md
  • examples/smart-contracts/reentrancy-hunt.md
  • examples/web-apps/sql-injection-hunt.md
  • resources/sharp-edges-catalog.md
  • resources/variant-patterns.md
  • templates/variant-report.md

Open the folder on GitHubat commit 06b36b8

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sendaifun/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Vulnhunter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vulnhunter compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vulnhunter this skillsendaifun/skills1301 repos~2.3kAutomated safety check: PassApache-2.0
Semgrepvigolium/piolium1401 repos~2.4kAutomated safety check: NotesMIT
C To AstNarwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.5k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
LLM Sast ScannerSunWeb3Sec/llm-sast-scanner288—~6.2kAutomated safety check: PassNone
Sast SemgrepAgentSecOps/SecOpsAgentKit2202 repos~2.4kAutomated safety check: PassCustom licence

Similar skills

  • Semgrep

    vigolium/piolium

    Run Semgrep static analysis scan on a codebase using parallel subagents.

    140 GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • C To Ast

    Narwhal-Lab/MagicSkills

    Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

    316 GitHub stars~1.1k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.5k GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • LLM Sast Scanner

    SunWeb3Sec/llm-sast-scanner

    General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.

    288 GitHub stars~6.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Sast Semgrep

    AgentSecOps/SecOpsAgentKit

    Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

    220 GitHub starsUsed in 2 repos~2.4k tokens
    SecurityAuto-check passed
  • Wp Phpstan

    Automattic/agent-skills

    A skill your agent uses when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and…

    211 GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check passed

More from sendaifun/skills

All 24 skills in this repo
  • Breaks a shared video or GIF down frame by frame to recreate its motion as working code instead of guessing the timing by eye.

    130 GitHub stars~2.1k tokensUpdated 2 mo ago
    Auto-check passed
  • Builds and debugs Arcium encrypted computation apps on Solana: Arcis circuits, Anchor orchestration, encrypted inputs and the init, queue and callback flow.

    130 GitHub stars~2.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Coingecko

    sendaifun/skills

    Complete CoinGecko Solana API integration for token prices, DEX pool data, OHLCV charts, trades, and market analytics.

    130 GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check: notes
  • Phantom Connect SDK

    sendaifun/skills

    Integrates Phantom wallet connection, social login, and transaction signing into React, React Native, or vanilla JS apps on Solana.

    130 GitHub stars~1.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Integrating Jupiter

    sendaifun/skills

    Comprehensive guidance for integrating Jupiter APIs (Ultra Swap, Lend, Perps, Trigger, Recurring, Tokens, Price, Portfolio, Prediction Markets, Send, Studio, Lock, Routing).

    130 GitHub starsUsed in 1 repo~5.1k tokens
    Auto-check passed
  • Pinocchio Development

    sendaifun/skills

    Comprehensive guide for building high-performance Solana programs using Pinocchio - the zero-dependency, zero-copy framework.

    130 GitHub starsUsed in 1 repo~4.1k tokens
    Auto-check passed

Categories

Questions about Vulnhunter

What does Vulnhunter do?

Security vulnerability detection and variant analysis skill. Vulnhunter is an agent skill from sendaifun/skills. Security vulnerability detection and variant analysis skill.

When should I use Vulnhunter?

Vulnhunter fits situations like: hunting for dangerous APIs; footgun patterns; error-prone configurations; vulnerability variants across codebases.

How do I install Vulnhunter in Claude Code?

Run `npx skills add sendaifun/skills --skill vulnhunter -a claude-code`. Or copy the skill folder (skills/vulnhunter in sendaifun/skills) into .claude/skills/vulnhunter in your project. Claude Code loads it when a task matches its description.

How do I install Vulnhunter in Codex?

Run `npx skills add sendaifun/skills --skill vulnhunter -a codex`. Or copy the skill folder (skills/vulnhunter in sendaifun/skills) into .agents/skills/vulnhunter in your project. Codex loads it when a task matches its description.

Can I use Vulnhunter in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sendaifun/skills --skill vulnhunter -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vulnhunter, .gemini/skills/vulnhunter, .github/skills/vulnhunter and .opencode/skills/vulnhunter in your project.

What does Vulnhunter need to run?

SKILL.md names no scripts, command-line tools or credentials: Vulnhunter is instructions for the agent only. Our summary lists: Python 3.

Does Vulnhunter access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vulnhunter safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vulnhunter use?

Vulnhunter is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vulnhunter use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vulnhunter?

Skills that share tags, products or a category with Vulnhunter: Semgrep (vigolium/piolium, 140 stars), C To Ast (Narwhal-Lab/MagicSkills, 316 stars), Semgrep Security Scan (trailofbits/skills, 7.5k stars) and LLM Sast Scanner (SunWeb3Sec/llm-sast-scanner, 288 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vulnhunter?

sendaifun (a GitHub organization) maintains it in sendaifun/skills, which has 130 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on July 31, 2026.

Source: sendaifun/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.