Install the "hunt-ntlm-info" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-ntlm-info into .claude/skills/hunt-ntlm-info/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-ntlm-info", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-ntlm-info -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "hunt-ntlm-info" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-ntlm-info into .agents/skills/hunt-ntlm-info/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-ntlm-info", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-ntlm-info -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "hunt-ntlm-info" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-ntlm-info into .cursor/skills/hunt-ntlm-info/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-ntlm-info", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-ntlm-info -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "hunt-ntlm-info" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-ntlm-info into .gemini/skills/hunt-ntlm-info/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-ntlm-info", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-ntlm-info -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "hunt-ntlm-info" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-ntlm-info into .github/skills/hunt-ntlm-info/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-ntlm-info", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-ntlm-info -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "hunt-ntlm-info" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-ntlm-info into .opencode/skills/hunt-ntlm-info/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-ntlm-info", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
hunt-ntlm-info
GitHub stars
47k
Used in
1 other repo
Token cost
~4.7k tokens
SKILL.md length
1,788 words
Files
1
Skills in repo
1,497
Repo updated
First seen
Licence
MIT
At a glance
Hunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange.
Works in 8 steps: Probe every anonymous endpoint for… → Send a valid NTLMSSP Type-1 message… → Use a keep-alive raw socket, not Python… → …
Tasks that involve Cloud office suites
SKILL.md covers Crown Jewel Targets, Attack Surface Signals, Step-by-Step Hunting Methodology and Payload & Detection Patterns, plus 7 more sections
Calls curl; reaches login.microsoftonline.com
What it does
Hunt Ntlm Info is an agent skill from sickn33/agentic-awesome-skills. Hunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange.
Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not…
It sits in Documents & Office, covering Cloud office suites. It works with Microsoft SharePoint. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.
When your agent uses it
Tasks that involve Cloud office suites
Example prompts
“/hunt-ntlm-info”
Requirements
Python 3
Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.
Workflow steps
8 steps, taken from the first numbered list in SKILL.md.
1Probe every anonymous endpoint for WWW-Authenticate: NTLM. Send a vanilla GET and inspect response headers. If NTLM is offered, proceed.
2Send a valid NTLMSSP Type-1 message anonymously. The Type-1 base64 below requests NetBIOS-domain and Workstation info from the server
3Use a keep-alive raw socket, not Python requests / curl one-shot. Most HTTP libraries close the connection between the Type-1 send and…
4Parse the Type-2 challenge from the WWW-Authenticate: NTLM response header. Base64-decode the value. The structure is NTLMSSP per MS-NLMP
5Decode the AV_PAIRS. The AvIds you care about
6Map findings to severity tier
7Check the timestamp. If AV[7] returns a current FILETIME within ~5s of Date: header, the system clock is synced — useful intel for…
8Cross-reference with subdomain enum. The DNS Tree name often reveals the parent forest — e.g. customer.parent-corp.example reveals the…
What it can do on your machine
Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
curl
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
login.microsoftonline.com
Also links to:
github.com
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Compatibility
Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.
From compatibility in the SKILL.md frontmatter.
Context cost
Hunt Ntlm Info loads about 4.7k tokens when it runs. Until then it costs about 26 tokens; SKILL.md has 1,788 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~26
When it runs· the whole SKILL.md, loaded when a task matches
~4.7k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/hunt-ntlm-info/SKILL.md (or your agent's skills folder).
name
hunt-ntlm-info
description
Hunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange.
compatibility
Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.
⚠️ AUTHORIZED USE ONLY
This skill is for educational purposes or authorized security assessments only.
You must have explicit, written permission from the system owner before using this tool.
Misuse of this tool is illegal and strictly prohibited.
Mandatory confirmation gate
Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:
Ask the user to state the exact target URL, IP, account, or resource.
Ask the user to confirm written authorization and the permitted scope.
Show the exact command(s) and explain their expected effect.
Wait for explicit confirmation in the current conversation.
Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
Crown Jewel Targets
NTLM info disclosure is a Medium-severity finding when chained to context — the leak itself is intentional protocol behavior (RFC-compliant NTLMSSP challenge), but on internet-exposed enterprise infrastructure it provides exact reconnaissance for the next stage of an attack. Highest-value targets:
Internet-reachable IIS / SharePoint / Exchange / OWA with dual-auth (Forms + NTLM, or NTLM + Kerberos)
Citrix NetScaler / VMware Horizon View internet-facing gateways with NTLM-backed AD auth
Lync / Skype for Business / Teams On-Prem edge servers
WSUS / Windows Update Services with NTLM-protected admin paths
CIFS-style fileshare proxies (HCL Sametime, IBM Notes Domino) that proxy NTLM
Legacy SharePoint farms that left NTLM enabled on the public-zone IIS binding
What makes this pay:
Internal AD domain disclosure (parent-forest mapping, e.g. customer.parent-corp.example → tenant inside corporate-AD tree)
This is the standard test Type-1 with negotiate flags NTLMSSP_NEGOTIATE_UNICODE | NTLMSSP_NEGOTIATE_OEM | NTLMSSP_NEGOTIATE_NTLM | NTLMSSP_NEGOTIATE_ALWAYS_SIGN | NTLMSSP_NEGOTIATE_KEY_EXCH | NTLMSSP_NEGOTIATE_56 | NTLMSSP_NEGOTIATE_128 | NTLMSSP_NEGOTIATE_TARGET_INFO. The OS Version field (06 01 B1 1D 00 00 00 0F) is Windows 7 build 7601 — accepted by virtually every NTLM responder.
Use a keep-alive raw socket, not Python requests / curl one-shot. Most HTTP libraries close the connection between the Type-1 send and Type-2 reception. Use one of:
Burp Repeater with Connection: keep-alive set explicitly
Combine with hunt-auth-bypass Legacy-Protocol Matrix findings on the same host → upgrade the auth-bypass finding's severity since the attacker has UPN/SAM format ready
Check the timestamp. If AV[7] returns a current FILETIME within ~5s of Date: header, the system clock is synced — useful intel for Kerberos golden-ticket forging (out of bug-bounty scope but red-team relevant).
Cross-reference with subdomain enum. The DNS Tree name often reveals the parent forest — e.g. customer.parent-corp.example reveals the customer is a sub-domain INSIDE corporate-parent AD, not a separate tenant. This is a privacy / topology-disclosure escalation that programs sometimes accept as Medium.
Payload & Detection Patterns
Generic NTLM Type-1 anonymous probe (curl + raw socket fallback):
bash
# Most one-shot curl runs DON'T return Type-2 because the connection closes.
# Use this as a quick probe to confirm NTLM is offered:
curl -sk -I -H "Authorization: NTLM TlRMTVNTUAABAAAAB4IIogAAAAAAAAAAAAAAAAAAAAAGAbEdAAAADw==" \
"https://target.example/_api/web/CurrentUser" 2>&1 | grep -i "WWW-Authenticate"
Burp send_http1_request (recommended for full Type-2 capture):
import socket, ssl, base64, struct, re
from datetime import datetime, timezone
HOST = "target.example"
ctx = ssl.create_default_context()
ctx.check_hostname = False
ctx.verify_mode = ssl.CERT_NONE
s = ctx.wrap_socket(socket.create_connection((HOST, 443)), server_hostname=HOST)
s.sendall(
f"GET /_api/web/CurrentUser HTTP/1.1\r\n"
f"Host: {HOST}\r\n"
"Authorization: NTLM TlRMTVNTUAABAAAAB4IIogAAAAAAAAAAAAAAAAAAAAAGAbEdAAAADw==\r\n"
"User-Agent: Mozilla/5.0\r\nConnection: keep-alive\r\n\r\n".encode()
)
data = b""
while True:
chunk = s.recv(8192)
if not chunk: break
data += chunk
if b"\r\n\r\n" in data: break
m = re.search(rb"WWW-Authenticate:\s*NTLM\s+([A-Za-z0-9+/=]{20,})", data, re.I)
if m:
b = base64.b64decode(m.group(1).decode("ascii"))
assert b[:8] == b"NTLMSSP\x00"
tn_len, _, tn_off = struct.unpack_from('<HHI', b, 12)
ti_len, _, ti_off = struct.unpack_from('<HHI', b, 40)
print(f"TargetName: {b[tn_off:tn_off+tn_len].decode('utf-16-le', errors='ignore')!r}")
av_types = {1:'NetBIOS Computer Name', 2:'NetBIOS Domain Name',
3:'DNS Computer Name', 4:'DNS Domain Name',
5:'DNS Tree Name', 7:'Timestamp', 9:'Target Name'}
i = 0
ti = b[ti_off:ti_off+ti_len]
while i < len(ti):
av_id, av_len = struct.unpack_from('<HH', ti, i)
if av_id == 0: break
val = ti[i+4:i+4+av_len]
if av_id == 7:
ts = struct.unpack('<Q', val[:8])[0]
secs = (ts - 116444736000000000) / 10000000
vs = datetime.fromtimestamp(secs, tz=timezone.utc).isoformat()
else:
vs = val.decode('utf-16-le', errors='ignore')
print(f" AV[{av_id}] {av_types.get(av_id, '?'):28s}: {vs!r}")
i += 4 + av_len
Burp Collaborator NOT needed for this finding class — the data leak is in the synchronous response, not via OOB.
Common Root Causes
Dual-auth IIS bindings on the public zone. Administrators leave NTLM enabled on the public-facing IIS site even when Forms auth is the intended entry point. Internal users get SSO; external attackers get the AD topology leak.
Default IIS Application Pool identity left as ApplicationPoolIdentity. Combined with default hostname, signals provisioning never went past first-boot.
Server never renamed from Windows-installer-generated hostname. Microsoft's default WIN-XXXXXXXXXXX 11-character pattern is the immediate tell. Sometimes also WORKGROUP\WIN-... in older boxes.
Sub-domain joined to corporate forest without zone-isolation. European-integrator case: a a European importer's SharePoint test environment is a child domain inside a corporate global AD, disclosed via NTLM DNS Tree Name. The customer probably intends customer.parent-corp.example to be operationally separate but the NTLM Type-2 reveals the forest membership to anyone who probes.
IIS Extended Protection NOT enabled. When <system.webServer><security><authentication><windowsAuthentication extendedProtection> is None (the default), the NTLM challenge is sent to any anonymous client. When set to Required, NTLM is restricted to authenticated callers — and the AV-pair leak is mitigated.
No WindowsAuthentication removed from applicationHost.config for internet-exposed sites. SharePoint Central Admin sometimes leaves this enabled even when SP zone configuration only enables Forms.
Bypass Techniques
This skill describes a disclosure leak, not an authentication bypass. The "bypass" question is: how do defenders block this AV-pair leak while still allowing legitimate NTLM auth?
Defense
Effectiveness
Disable NTLM on the public IIS binding entirely (Forms-only)
Best — eliminates the surface
IIS Extended Protection = Required
Restricts NTLM challenge to authenticated callers; AV-pair leak mitigated
Reverse-proxy strip WWW-Authenticate from anonymous responses
Sometimes works but breaks legitimate clients
Rate-limit the Type-1 → Type-2 endpoint
Doesn't prevent disclosure, only slows enumeration
Rename the Windows host from WIN-XXXXXXXXXXX
Removes the "lazy provisioning" tell; doesn't stop the leak
Move the SP/Exchange farm to a child AD with no cross-trust to corporate
Mitigates the forest disclosure; doesn't stop the leak
For the attacker: there's no "bypass" needed — the leak is the finding.
Show full SKILL.md (729 more words)Show less
Gate 0 Validation
Before writing the report, confirm:
What can the attacker do RIGHT NOW with this disclosure?
Internet-exposed + default hostname + corporate forest disclosed → Medium: attacker has UPN format for hunt-auth-bypass matrix probes, plus knows server has likely-default service accounts.
Intranet-only or only NetBIOS name → Informational.
Does the program accept information-disclosure findings without a chained impact?
Many programs (Microsoft, large enterprise VDPs) DO accept this when the leaked info includes internal AD topology.
Many programs (Shopify, GitHub) reject info disclosure without a chained impact.
Read the program scope before submitting; if borderline, chain with a Tier-A finding from hunt-auth-bypass.
Can you reproduce in <5 minutes from a fresh shell?
The Python snippet above is the canonical reproduction. Include it verbatim in the report.
Real Impact Examples
Scenario A — Enterprise SharePoint inside parent corporate AD
Target: https://target-portal.example/ — a enterprise dealer portal (test mirror) operated by a system integrator.
Sending the anonymous Type-1 message to /_api/web/CurrentUser returned a Type-2 challenge whose AV_PAIRS decoded to:
NetBIOS Domain Name: <CustomerName>
NetBIOS Computer Name: WIN-XXXXXXXXXXX
DNS Domain Name: customer.parent-corp.example
DNS Computer Name: WIN-XXXXXXXXXXX.customer.parent-corp.example
DNS Tree Name: customer.parent-corp.example
Timestamp: 2026-05-13T15:55:37.922Z
Three escalation paths:
Default Windows-installer hostname (WIN-XXXXXXXXXXX) — server was never renamed after OS install; strong signal of lazy provisioning. Likely default service-account passwords on the SQL backend, default WSUS config, etc.
Sub-domain inside corporate-parent AD (customer.parent-corp.example) — the customer is a child domain inside <ParentCorp>'s global Active Directory. A compromise of this test farm has potential cross-trust to corporate-parent.
UPN format known — combined with hunt-auth-bypass's discovery of an anonymous brute-force endpoint on /_vti_bin/Authentication.asmx, the attacker has both the credential format (firstname.lastname@customer.parent-corp.example or <CustomerName>\firstname.lastname) and the unlimited submission endpoint.
Reported severity: Medium, with a note that the chain with the Authentication.asmx anonymous brute-force makes the combined attack Critical.
Scenario B — Exchange edge with NTLM-protected EWS
Target: https://mail.example.com/EWS/Exchange.asmx. Type-1 probe returns Type-2 with DNS Tree Name corp.example.com and DNS Computer Name MAIL01.corp.example.com. Confirms the Exchange edge is domain-joined to corporate AD (rather than running in a DMZ-isolated AD). For an attacker with the matching hunt-mfa-bypass / hunt-auth-bypass chain, the leaked UPN format and server-name format accelerate credential spraying by removing the recon step. Reported severity: Low-Medium depending on program.
Scenario C — Intranet-only intentional leak (not a finding)
Target: https://intranet.corp.example (clearly internal, behind VPN). Type-1 returns full AV-pair set. Not reportable — this is intended NTLM behavior on intranet, and the disclosure is to authenticated VPN users who already see the same data via nltest /dsgetdc:corp.example.com. Recognize and drop.
Related Skills & Chains
hunt-sharepoint — SharePoint farms emit anonymous Type-2 challenges on /_vti_bin/ by default; this is one of the most reliable ways to get internal AD topology. Chain primitive: SharePoint discovered → NTLM Type-2 capture on /_vti_bin/Lists.asmx → hunt-ntlm-info AV_PAIR decode → internal forest name → m365-entra-attack ROPC spray on Entra tenant tied to that forest.
m365-entra-attack — Leaked NetBIOS domain + UPN suffix is the missing piece for a credible password spray. Chain primitive: NTLM Type-2 yields corp.example.com DNS tree → cross-reference Entra tenant via https://login.microsoftonline.com/corp.example.com/.well-known/openid-configuration → m365-entra-attack AADSTS error-differential username enumeration on resolved tenant.
hunt-aspnet — IIS sites running ASP.NET frequently expose NTLM on management paths. Chain primitive: NTLM Type-2 on /owa/, /ecp/, /rpc/, /aspnet_client/ → confirm IIS + ASP.NET version → hunt-aspnet ViewState / .axd enumeration on same host.
offensive-osint — The hostname pattern WIN-XXXXXXXXXXX signals lazy provisioning and predicts other weak hygiene. Chain primitive: NTLM Type-2 returns default-installer hostname → flag as low-maturity environment → offensive-osint deep recon (cert transparency, GitHub leakage, breach corpus correlation) is high-yield on this org.
triage-validation — Most NTLM info-disclosure findings die at the 7-Question Gate on "is this exploitable" — pure topology disclosure is Low/Informational. Chain primitive: pull every NTLM-info finding through triage-validation BEFORE writing it up; only report if (a) leaks UPN format that accelerates spray, or (b) leaks production hostname mapping (redteam-report-template for the chain-narrative).
When to Use
You have explicit, written authorization to assess the target in scope, and the task matches this skill's vulnerability class or technique within a bug-bounty or penetration-test engagement.
You need the recon, exploitation, or validation workflow described below — executed strictly inside the approved scope.
Limitations
Authorized scope only: the confirmation gate above is mandatory before any probing, exploitation, or credential-access command.
Docs-only import: upstream helper scripts, commands, engine, and research assets are not bundled; reinstall tooling from the source repo when needed.
Validate every finding (see triage-validation) before reporting; report via report-writing. Prefer a sandbox, disposable VM, or controlled lab.
Example
bash
# Read-only first step; confirm scope before anything active.
cat scope.txt # target list from the authorized engagement brief
Adapted from elementalsouls/Claude-BugHunter (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: executable helpers, commands, engine, and research assets not bundled.
We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
Hunt Ntlm Info next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Hunt Ntlm Info compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Hunt Ntlm Info this skillsickn33/agentic-awesome-skills
Distill a colleague into a reusable AI skill (work + persona) using tool connections — Slack, Slack AI, Jira, GHE, Bitbucket, Confluence, SharePoint, Teams, Outlook, Notion, Linear, Google Docs, and…
Work with Microsoft 365 services via the Graph API — emails, calendar events, SharePoint sites (read and write), Teams chats and channel messages, OneDrive files, OneNote notebooks, Planner task…
Guides work with Outlook, OneDrive, SharePoint, Teams, Excel, To Do and Planner through aai-cli's Microsoft Graph commands, starting from which service owns the data.
Analyze the current SharePoint document library in read-only mode and produce a structured summary of files, folders, file types, recent activity, naming issues, and organization recommendations.
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
Hunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange. Hunt Ntlm Info is an agent skill from sickn33/agentic-awesome-skills. Hunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange.
When should I use Hunt Ntlm Info?
Hunt Ntlm Info fits situations like: tasks that involve Cloud office suites.
How do I install Hunt Ntlm Info in Claude Code?
Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-ntlm-info -a claude-code`. Or copy the skill folder (skills/hunt-ntlm-info in sickn33/agentic-awesome-skills) into .claude/skills/hunt-ntlm-info in your project. Claude Code loads it when a task matches its description.
How do I install Hunt Ntlm Info in Codex?
Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-ntlm-info -a codex`. Or copy the skill folder (skills/hunt-ntlm-info in sickn33/agentic-awesome-skills) into .agents/skills/hunt-ntlm-info in your project. Codex loads it when a task matches its description.
Can I use Hunt Ntlm Info in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill hunt-ntlm-info -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-ntlm-info, .gemini/skills/hunt-ntlm-info, .github/skills/hunt-ntlm-info and .opencode/skills/hunt-ntlm-info in your project.
What does Hunt Ntlm Info need to run?
Going by SKILL.md and its folder, Hunt Ntlm Info needs the command-line tools its instructions call (curl). Our summary lists: Python 3. Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled..
Does Hunt Ntlm Info access the network?
SKILL.md names 2 domains. In commands or code: login.microsoftonline.com; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.
Is Hunt Ntlm Info safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Hunt Ntlm Info use?
Hunt Ntlm Info is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Hunt Ntlm Info use?
About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Hunt Ntlm Info?
Skills that share tags, products or a category with Hunt Ntlm Info: Colleague Distillation (ZhixiangLuo/10xProductivity, 479 stars), Msgraph (codemie-ai/codemie-code, 294 stars), aai-cli Microsoft 365 (aai-labs/agent-barn, 109 stars) and Workiq (microsoft/work-iq, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Hunt Ntlm Info?
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.