Agent skill

Hunt Dispatch

by sickn33 in sickn33/agentic-awesome-skills

Skill-set loader for /hunt orchestrator. An agent skill from sickn33/agentic-awesome-skills.

MITAuto-check: notes

Install Hunt Dispatch

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-dispatch -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills hunt-dispatch --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-dispatch .claude/skills/hunt-dispatch && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-dispatch
GitHub stars
47k
Used in
1 other repo
Token cost
~5k tokens
SKILL.md length
1,721 words
Files
1
Skills in repo
1,394
Repo updated
First seen
Licence
MIT

At a glance

Skill-set loader for /hunt orchestrator. An agent skill from sickn33/agentic-awesome-skills.

  • Works in 5 steps: 404 baseline (ALL modes, mandatory,… → fingerprint (red team only) → load skill set → …
  • SKILL.md covers engagement context, step 0 — 404 baseline (ALL…, step 1 — fingerprint (red team… and step 2 — load skill set, plus 7 more sections
  • Calls curl, php and kubectl

What it does

Hunt Dispatch is an agent skill from sickn33/agentic-awesome-skills. Skill-set loader for /hunt orchestrator.

Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not…

The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

Example prompts

  • “/hunt-dispatch”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. 404 baseline (ALL modes, mandatory, before any enumeration)
  2. fingerprint (red team only)
  3. load skill set
  4. taxonomy print (once, at session start)
  5. return control to /hunt

What it can do on your machine

Read from SKILL.md and the folder at commit 1e53ce2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • php
    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Hunt Dispatch loads about 5k tokens when it runs. Until then it costs about 14 tokens; SKILL.md has 1,721 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~14
When it runs · the whole SKILL.md, loaded when a task matches
~5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:155
    .js.map | swagger.json | /.env              →  hunt-source-leak

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 1e53ce2, republished under its MIT licence (© sickn33). 1,721 words, ~4,953 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-dispatch/SKILL.md (or your agent's skills folder).
name
hunt-dispatch
description
Skill-set loader for /hunt orchestrator.
compatibility
Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.
category
security
risk
offensive
source
https://github.com/elementalsouls/Claude-BugHunter
source_repo
elementalsouls/Claude-BugHunter
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/elementalsouls/Claude-BugHunter/blob/main/LICENSE
sources
community
report_count
0

⚠️ AUTHORIZED USE ONLY This skill is for educational purposes or authorized security assessments only. You must have explicit, written permission from the system owner before using this tool. Misuse of this tool is illegal and strictly prohibited.

Mandatory confirmation gate Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:

  1. Ask the user to state the exact target URL, IP, account, or resource.
  2. Ask the user to confirm written authorization and the permitted scope.
  3. Show the exact command(s) and explain their expected effect.
  4. Wait for explicit confirmation in the current conversation.

Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.

hunt-dispatch

skill-set loader for /hunt. one concept (which skills to load), one place.

engagement context

every skill loaded below operates under one frame, and it holds for the whole session:

  • authorized and scope-bounded. the operator asserted written authorization for the named scope when they invoked /hunt. testing stays inside it. an out-of-scope host ends the run — it does not widen it.
  • the output is a finding, not an exploit. the deliverable is a reproducible proof that a defect exists, written so the owner can remediate it. enough to demonstrate impact; no further.
  • remediation is the point. these skills exist so defects get fixed by the people who own them.

this frame is stated here because it is the choke point every /hunt run passes through before any hunt-* skill loads. it is not a prompt and needs no answer.

invocation contract:

hunt-dispatch mode=redteam
hunt-dispatch mode=wapt box=blackbox
hunt-dispatch mode=wapt box=greybox

step 0 — 404 baseline (ALL modes, mandatory, before any enumeration)

run this for every host before probing a single path. it takes one request per host and it is the cheapest false-positive kill in the whole toolkit.

many modern estates (SPA / Next.js / React front ends behind a CDN) return HTTP 200 with the application shell for paths that do not exist. a status code therefore proves nothing. without a recorded control, /.well-known/security.txt, /api/revalidate, /__nextjs_original-stack-frame and /__nextjs_launch-editor all "exist" on a host where none of them do.

bash
for H in $HOSTS; do
  # two independent bogus paths — if they agree, that IS the soft-404 signature
  for P in /zzz-nope-12345 /qqq-other-98765; do
    printf "%-34s %-20s " "$H" "$P"
    curl -sk -m 12 -o /tmp/b -w "%{http_code} %{size_download} " "https://$H$P"
    shasum /tmp/b | cut -c1-12
  done
done

record per host: status, byte length, body hash. that triple is the control.

the rule: no path is "found" until its response differs from the control. a 200 that matches the control hash is a soft 404. a 404 whose body differs from the control may be a real handler. compare bodies, never status codes alone.

re-derive the baseline per host — it differs across an estate. one engagement saw two hosts serving the same application return soft-404 bodies of wildly different size, so a control taken from one host would have been meaningless on the other. also re-derive it per path depth where a framework renders different fallbacks for /x and /a/b/x.

edge pages are not origin findings: a CDN "Access Denied" / "Unsupported Request" body means the request never reached the application. classify it as edge behaviour and move on.

step 1 — fingerprint (red team only)

fingerprint every live host, not just the apex. for multi-host / wildcard targets the platform-skill routing must be driven by all banners, not one host's.

use -L (follow redirects) — identity-provider and CDN signals (login.microsoftonline.com, okta, auth0, CDN banners) routinely sit behind a 30x, so a no-redirect curl -sI silently misses those matches. pull both headers and the landing-page HTML (__NEXT_DATA__, VIEWSTATE, laravel_session, Ignition, framework markers live in the body, not headers).

bash
HOSTS="$TARGET"
if [ -f "recon/$TARGET/live-hosts.txt" ]; then
  HOSTS=$(cat "recon/$TARGET/live-hosts.txt")
fi
for H in $HOSTS; do
  echo "=== $H ==="
  # -L follow redirects, -D - dump headers, -o body; cap body to keep context small
  curl -sSL -m 12 -D - -o /tmp/fp_body "https://$H" 2>/dev/null | tr -d '\r'
  # surface body-only platform markers
  grep -aoE '__NEXT_DATA__|/_next/|VIEWSTATE|rO0[AB]|laravel_session|Ignition|Telescope|Whitelabel|/actuator|application/grpc|socket\.io|swagger|\.js\.map' \
    /tmp/fp_body | sort -u
done
rm -f /tmp/fp_body

if live-hosts.txt is absent, the loop still runs once against $TARGET. record which signal came from which host — a platform skill matched on host B does not imply host A runs that stack.

look for the following signals → platform skill mapping:

okta.com | auth0.com | pingidentity         →  okta-attack
login.microsoftonline.com | outlook | sts   →  m365-entra-attack
pulse | fortinet | ivanti | citrix          →  enterprise-vpn-attack
vsphere | vcenter | :9443                   →  vmware-vcenter-attack
amazonaws | azure | googleapis | gcp        →  cloud-iam-deep
github.com/<org>/                           →  supply-chain-attack-recon
.apk | play.google.com                      →  apk-redteam-pipeline
MongoDB | mongoose | CouchDB | Redis        →  hunt-nosqli
?page= | ?file= | ?path= | php wrapper      →  hunt-lfi
rO0A | VIEWSTATE | rememberMe cookie        →  hunt-deserialization
Access-Control-Allow-Origin header          →  hunt-cors
/forgot-password | /reset | X-Forwarded    →  hunt-host-header
?redirect= | ?next= | ?return= | ?url=     →  hunt-open-redirect
OTP | /verify | /2fa | no-rate-limit        →  hunt-brute-force
Set-Cookie session | PHPSESSID              →  hunt-session
Active Directory | LDAP | OpenLDAP | ADFS  →  hunt-ldap
__NEXT_DATA__ | /_next/ | buildId           →  hunt-nextjs
X-Powered-By: Express | Node.js | .js stack →  hunt-nodejs
postMessage | dangerouslySetInnerHTML        →  hunt-dom
WebSocket | ws:// | socket.io               →  hunt-websocket
gRPC | :50051 | application/grpc            →  hunt-grpc
laravel_session | Ignition | Telescope       →  hunt-laravel
X-Application-Context | Whitelabel | /actuator → hunt-springboot
:6443 | :10250 | :2379 | kubectl            →  hunt-k8s
.github/workflows | Jenkins | GitLab CI     →  hunt-cicd
.js.map | swagger.json | /.env              →  hunt-source-leak
HSTS missing | SPF | DMARC | AXFR           →  hunt-tls-network
conflict resolution & load budget

real targets almost always return multiple signals at once — e.g. a single host can show Cloudflare (CDN) + login.microsoftonline.com (redirect) + __NEXT_DATA__ (Next.js front end) + amazonaws (origin) simultaneously. loading every match blindly can pull 20-plus skills and blow the context window, drowning the high-signal skill in noise. apply this precedence and cap:

priority order (load highest tiers first, stop at the cap):

tier 1  identity / SSO fabric    okta-attack, m365-entra-attack
        (own the auth boundary — highest blast radius if compromised)
tier 2  perimeter appliances     enterprise-vpn-attack, vmware-vcenter-attack
        (pre-auth RCE / direct internal foothold)
tier 3  cloud / IAM              cloud-iam-deep, hunt-cloud-misconfig
        (credential → lateral movement)
tier 4  app framework / stack    hunt-nextjs, hunt-nodejs, hunt-laravel,
        hunt-springboot, hunt-aspnet, hunt-sharepoint
tier 5  protocol / class signals hunt-nosqli, hunt-lfi, hunt-deserialization,
        hunt-cors, hunt-host-header, hunt-open-redirect, hunt-grpc,
        hunt-websocket, hunt-dom, hunt-k8s, hunt-cicd, hunt-source-leak,
        hunt-tls-network, hunt-ldap, hunt-brute-force, hunt-session

load budget: cap platform-skill loads at 8. if more than 8 match, keep the highest-tier 8 and drop the rest; print the dropped ones under deferred: in the taxonomy block so they can be loaded on demand later.

de-dup rules (avoid loading two skills for the same evidence):

  • CDN banner alone (Cloudflare/Akamai/Fastly) is not a platform match — it fingerprints the edge, not the app. do not load a skill for it; note it for hunt-cache-poison / hunt-http-smuggling, which the mode set already carries.
  • amazonaws / azure / googleapis in a header/origin → cloud-iam-deep. the same string found as a leaked key/JSON in a JS bundle or APK → still cloud-iam-deep, but flag it as a live-credential lead (higher priority, tier 3 becomes tier 1 for that host).
  • a framework marker (__NEXT_DATA__, laravel_session) and a generic class signal (?redirect=, Access-Control-Allow-Origin) on the same host → load the framework skill (tier 4) and keep the class skill only if budget remains; the WAPT/redteam mode set already loads the common class skills unconditionally.

step 2 — load skill set

invoke each skill in order via the Skill tool.

mode=redteam

always-on (load first):

redteam-mindset
mid-engagement-ir-detection

platform (load second, conditional on fingerprint matches from step 1):

okta-attack
m365-entra-attack
enterprise-vpn-attack
vmware-vcenter-attack
cloud-iam-deep
supply-chain-attack-recon
apk-redteam-pipeline

high-impact hunt-* set (load third):

hunt-rce
hunt-sqli
hunt-ssrf
hunt-ato
hunt-auth-bypass
hunt-saml
hunt-oauth
hunt-mfa-bypass
hunt-file-upload
hunt-http-smuggling
hunt-cloud-misconfig
hunt-sharepoint
hunt-aspnet

report format: redteam-report-template (subject / observations / description / impact / recommendation / poc).

mode=wapt

always-on:

bb-methodology
security-arsenal
triage-validation

full hunt-* set (all OWASP-relevant):

hunt-xss             hunt-sqli            hunt-ssrf            hunt-idor
hunt-csrf            hunt-xxe             hunt-rce             hunt-graphql
hunt-oauth           hunt-saml            hunt-mfa-bypass      hunt-auth-bypass
hunt-ato             hunt-file-upload     hunt-business-logic  hunt-race-condition
hunt-llm-ai          hunt-api-misconfig   hunt-ssti            hunt-cache-poison
hunt-http-smuggling  hunt-subdomain       hunt-cloud-misconfig hunt-misc
hunt-aspnet          hunt-sharepoint      hunt-ntlm-info
hunt-lfi             hunt-nosqli          hunt-deserialization
hunt-cors            hunt-host-header     hunt-open-redirect
hunt-brute-force     hunt-session         hunt-ldap
hunt-nextjs          hunt-nodejs          hunt-dom
hunt-websocket       hunt-grpc            hunt-laravel
hunt-springboot      hunt-k8s             hunt-cicd
hunt-source-leak     hunt-tls-network

report format: report-writing (bugcrowd-reporting if the target is on bugcrowd).

box=greybox: creds already captured by /hunt, available in session memory.

do not fan out across the authenticated hunt-* set until the creds are validated. /hunt only prompts for and stores creds (commands/hunt.md) — it does not confirm they work. firing every authenticated test with dead, MFA-gated, or wrong-role creds wastes the whole run and produces false "no auth surface" conclusions. run a single low-cost auth preflight first:

bash
# session-cookie creds: one authenticated GET against an identity echo endpoint
curl -sS -m 12 -b "$SESSION_COOKIE" "https://$TARGET/api/me" -w '\n%{http_code}\n'
#   200 + your username/email  → live session, role visible in body
#   401/403                    → dead or insufficient — STOP, re-auth

# bearer/JWT creds: same probe with Authorization
curl -sS -m 12 -H "Authorization: Bearer $TOKEN" \
  "https://$TARGET/api/me" -w '\n%{http_code}\n'

# raw user/pass: drive the real login flow once, capture Set-Cookie, then echo
#   watch for an MFA / step-up challenge in the response — if present, the creds
#   alone do not yield an authenticated session (see memory: operator-capability)

confirm three things from the preflight, and record them for the hunt-* skills:

  1. live — auth probe returns 200, not 401/403.
  2. role/privilege — the /api/me (or equivalent) body shows the expected role/tenant/scopes. IDOR and authz tests need a known baseline identity; a silently-admin or silently-readonly cred skews every authz finding.
  3. not MFA-gated — login did not stop at a 2fa/step-up challenge. if it did, you hold creds but not a session — default to least capability and confirm with the operator before claiming authenticated reach.

if the preflight fails, do not silently continue as blackbox — surface "greybox creds did not validate (HTTP {code} / MFA challenge)" so the operator can re-supply. only after a clean preflight: apply the validated session to every authenticated test.

Show full SKILL.md (639 more words)Show less

step 3 — taxonomy print (once, at session start)

emit a deterministic block. plain text, lowercase, colon-delimited, no decoration.

mode=redteam
loaded for red team: {N} skills
  mindset:    redteam-mindset
  platform:   {fingerprint-matched skills (<=8, tier order), or "none detected"}
  deferred:   {platform skills past the 8-cap, or omit line if none}
  auth:       hunt-ato, hunt-auth-bypass, hunt-saml, hunt-oauth, hunt-mfa-bypass
  inj:        hunt-rce, hunt-sqli, hunt-ssrf, hunt-file-upload
  infra:      hunt-http-smuggling, hunt-cloud-misconfig
  stack:      hunt-sharepoint, hunt-aspnet
  ir:         mid-engagement-ir-detection
mode=wapt
loaded for wapt ({blackbox|greybox}): {N} skills
  inj:        hunt-xss, hunt-sqli, hunt-ssrf, hunt-rce, hunt-xxe, hunt-ssti, hunt-file-upload
  authz:      hunt-idor, hunt-auth-bypass, hunt-ato
  auth:       hunt-oauth, hunt-saml, hunt-mfa-bypass
  api:        hunt-graphql, hunt-api-misconfig
  logic:      hunt-business-logic, hunt-race-condition
  infra:      hunt-http-smuggling, hunt-cache-poison
  recon:      hunt-subdomain
  cloud:      hunt-cloud-misconfig
  ai:         hunt-llm-ai
  stack:      hunt-aspnet, hunt-sharepoint, hunt-ntlm-info
  misc:       hunt-misc, hunt-csrf
  reporting:  bb-methodology, security-arsenal, triage-validation

subagent scope inheritance

if any part of the hunt is delegated to subagents, scope does not inherit implicitly. every subagent prompt must carry:

  1. the authorized host list, verbatim, as data. not "the target estate", not "*.target.com" — the explicit list. a subagent cannot infer the boundary.
  2. the discovered-host rule: hosts found mid-run (via CT logs, CSP headers, JS bundles, CNAME chains, error messages) are report-only. resolve DNS, record, hand back. never probe, never write, until the operator re-authorizes.
  3. a deny-list of action-executing endpoints, applied BEFORE any allow-list. deny by verb-in-name first: refund, settle, payout, transfer, adjust, disburse, create, update, delete, rotate, reset, send, initiate, generate, process. only then allow read-shaped names. order matters — a path like refund/batch/status matches the read-shaped keyword "status" but is a refund route; an allow-list applied first would probe it.
  4. "read-only" spelled out as forbidden verbs, not as an adjective. "read-only" is routinely interpreted as "don't be destructive", which does not stop an agent sending {} to an endpoint whose name starts with generate* and creating a real record on production.

lesson from an authorized engagement: a subagent was told READ-ONLY and still (a) created a live record on production because it expected {} to return a validation error, and (b) wrote an object to a cloud bucket that was never on the authorized list — one the parent prompt had named only for a DNS check. both were disclosed in the deliverable. the fix is structural: pass scope as data, deny by verb before allowing by verb, and treat every discovered host as out of scope until told otherwise.

step 4 — return control to /hunt

after taxonomy print, hand control back to /hunt for step 3 (sibling delegation) and step 4 (active testing). do not run probes here — this skill only loads context.

privacy

never echo back, log, or persist:

  • SOW / scope-of-work / engagement-letter content
  • grey box credentials (kept in session memory by /hunt, never written to disk)
  • client identifiers in user-level memory

  • bb-methodology — When PART 0 mode confirmation completes. Workflow primitive: bb-methodology confirms engagement type (red team vs WAPT vs bug bounty); the answer feeds directly into this skill's mode=redteam / mode=wapt invocation.
  • redteam-mindset + mid-engagement-ir-detection — When mode=redteam is loaded. Workflow primitive: these are the always-on skills loaded first by step 2 of the redteam flow before any platform skill or hunt-* skill.
  • okta-attack / m365-entra-attack / enterprise-vpn-attack / vmware-vcenter-attack / cloud-iam-deep / supply-chain-attack-recon / apk-redteam-pipeline — When fingerprint signals match. Workflow primitive: step 1's curl fingerprint scan against recon/<target>/live-hosts.txt maps banner / domain signals to one or more of these platform skills.
  • hunt-rce / hunt-sqli / hunt-ssrf / hunt-ato / *all other hunt- skills** — When the mode-specific skill set is being printed. Workflow primitive: this skill is the loader; it names the hunt-* skills but does not run probes — actual hunting happens after step 4 returns control to /hunt`.
  • report-writing vs redteam-report-template — When the taxonomy print specifies the report format. Workflow primitive: mode=wapt ends with report-writing as the deliverable format; mode=redteam ends with redteam-report-template instead.

When to Use

  • You have explicit, written authorization to assess the target in scope, and the task matches this skill's vulnerability class or technique within a bug-bounty or penetration-test engagement.
  • You need the recon, exploitation, or validation workflow described below — executed strictly inside the approved scope.

Limitations

  • Authorized scope only: the confirmation gate above is mandatory before any probing, exploitation, or credential-access command.
  • Docs-only import: upstream helper scripts, commands, engine, and research assets are not bundled; reinstall tooling from the source repo when needed.
  • Validate every finding (see triage-validation) before reporting; report via report-writing. Prefer a sandbox, disposable VM, or controlled lab.
Example
bash
# Read-only first step; confirm scope before anything active.
cat scope.txt  # target list from the authorized engagement brief

Adapted from elementalsouls/Claude-BugHunter (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: executable helpers, commands, engine, and research assets not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt-dispatch of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 1e53ce2

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Hunt Dispatch next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Dispatch compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Dispatch this skillsickn33/agentic-awesome-skills47k1 repos~5kAutomated safety check: NotesMIT
Team Agent Orchestrationaffaan-m/ECC274k1 repos~1.2kAutomated safety check: PassMIT
Orca Orchestrationstablyai/orca87k—~916Automated safety check: PassMIT
Agent Orchestrator Taskruvnet/ruflo74k3 repos~1kAutomated safety check: PassMIT
Plan Orchestrateaffaan-m/ECC274k1 repos~4.5kAutomated safety check: PassMIT
Swarm Orchestrationruvnet/ruflo74k2 repos~779Automated safety check: PassMIT

Similar skills

  • Run team-based orchestration for agent squads: work items with owners and scope, agent Kanban state, branch isolation, control pane visibility, and merge gates.

    274k GitHub starsUsed in 1 repo~1.2k tokens
    Productivity & AutomationAuto-check passed
  • Orca Orchestration

    stablyai/orca

    Coordinate supervised Orca workers: threaded messages, blocking ask/reply, task dispatch, worker_done/escalation waits, task DAGs, decision gates, coordinator…

    87k GitHub stars~916 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Agent skill for orchestrator-task - invoke with $agent-orchestrator-task

    74k GitHub starsUsed in 3 repos~1k tokens
    Agent WorkflowsAuto-check passed
  • Plan Orchestrate

    affaan-m/ECC

    Read a plan document, decompose it into steps, design a per-step agent chain from the ECC catalogue, and emit ready-to-paste /orchestrate custom prompts.

    274k GitHub starsUsed in 1 repo~4.5k tokens
    Agent WorkflowsAuto-check passed
  • Coordinates a hierarchical swarm of specialized agents through the claude-flow CLI for work that spans several files or modules at once.

    74k GitHub starsUsed in 2 repos~779 tokens
    Agent WorkflowsAuto-check passed
  • Multi-agent swarm coordination for complex tasks. An agent skill from ruvnet/ruflo.

    74k GitHub stars~261 tokensUpdated today
    DevelopmentAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,394 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about Hunt Dispatch

What does Hunt Dispatch do?

Skill-set loader for /hunt orchestrator. An agent skill from sickn33/agentic-awesome-skills. Hunt Dispatch is an agent skill from sickn33/agentic-awesome-skills. Skill-set loader for /hunt orchestrator.

How do I install Hunt Dispatch in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-dispatch -a claude-code`. Or copy the skill folder (skills/hunt-dispatch in sickn33/agentic-awesome-skills) into .claude/skills/hunt-dispatch in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Dispatch in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-dispatch -a codex`. Or copy the skill folder (skills/hunt-dispatch in sickn33/agentic-awesome-skills) into .agents/skills/hunt-dispatch in your project. Codex loads it when a task matches its description.

Can I use Hunt Dispatch in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill hunt-dispatch -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-dispatch, .gemini/skills/hunt-dispatch, .github/skills/hunt-dispatch and .opencode/skills/hunt-dispatch in your project.

What does Hunt Dispatch need to run?

Going by SKILL.md and its folder, Hunt Dispatch needs the command-line tools its instructions call (curl, php and kubectl). Our summary lists: Node.js. Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled..

Does Hunt Dispatch access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Hunt Dispatch safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Hunt Dispatch use?

Hunt Dispatch is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Dispatch use?

About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Dispatch?

Skills that share tags, products or a category with Hunt Dispatch: Team Agent Orchestration (affaan-m/ECC, 274k stars), Orca Orchestration (stablyai/orca, 87k stars), Agent Orchestrator Task (ruvnet/ruflo, 74k stars) and Plan Orchestrate (affaan-m/ECC, 274k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Dispatch?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,304 GitHub stars. The repository holds 1,394 skills in this directory. The repository was last updated on October 6, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.