YugabyteDB ASH Instrumentation
yugabyte/yugabyte-db
Procedure for adding or changing YugabyteDB Active Session History wait states in TServer and DocDB C++ code, including the macro to use for sync and async paths.
Hunting skill for race condition vulnerabilities. An agent skill from sickn33/agentic-awesome-skills.
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-race-condition -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sickn33/agentic-awesome-skills hunt-race-condition --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-race-condition .claude/skills/hunt-race-condition && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hunt-race-condition" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-race-condition into .claude/skills/hunt-race-condition/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-race-condition", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-race-conditionType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-race-condition -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sickn33/agentic-awesome-skills hunt-race-condition --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/hunt-race-condition .agents/skills/hunt-race-condition && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hunt-race-condition" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-race-condition into .agents/skills/hunt-race-condition/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-race-condition", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-race-condition -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sickn33/agentic-awesome-skills hunt-race-condition --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/hunt-race-condition .cursor/skills/hunt-race-condition && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hunt-race-condition" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-race-condition into .cursor/skills/hunt-race-condition/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-race-condition", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sickn33/agentic-awesome-skills.git --path skills/hunt-race-condition--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-race-condition -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sickn33/agentic-awesome-skills hunt-race-condition --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/hunt-race-condition .gemini/skills/hunt-race-condition && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hunt-race-condition" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-race-condition into .gemini/skills/hunt-race-condition/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-race-condition", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sickn33/agentic-awesome-skills hunt-race-conditionInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-race-condition -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/hunt-race-condition .github/skills/hunt-race-condition && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hunt-race-condition" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-race-condition into .github/skills/hunt-race-condition/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-race-condition", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-race-condition -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sickn33/agentic-awesome-skills hunt-race-condition --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/hunt-race-condition .opencode/skills/hunt-race-condition && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hunt-race-condition" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-race-condition into .opencode/skills/hunt-race-condition/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-race-condition", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hunt-race-conditionHunting skill for race condition vulnerabilities. An agent skill from sickn33/agentic-awesome-skills.
Hunt Race Condition is an agent skill from sickn33/agentic-awesome-skills. Hunting skill for race condition vulnerabilities.
Its SKILL.md is about 5.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/details.md`). Compatibility notes: Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not…
It sits in Development, covering Async programming. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.
10 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
hackerone.comnvd.nist.govportswigger.netmedium.comflatt.techgithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.
From compatibility in the SKILL.md frontmatter.
Hunt Race Condition loads about 5.7k tokens when it runs, and up to ~9.4k if it reads all its reference files. Until then it costs about 17 tokens; SKILL.md has 2,394 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 2,394 words, ~5,708 tokens.
.claude/skills/hunt-race-condition/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.⚠️ AUTHORIZED USE ONLY This skill is for educational purposes or authorized security assessments only. You must have explicit, written permission from the system owner before using this tool. Misuse of this tool is illegal and strictly prohibited.
Mandatory confirmation gate Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:
- Ask the user to state the exact target URL, IP, account, or resource.
- Ask the user to confirm written authorization and the permitted scope.
- Show the exact command(s) and explain their expected effect.
- Wait for explicit confirmation in the current conversation.
Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
Winning a race needs requests that arrive in the same narrow window — sequential sends never
work. Use a single-packet / synchronized-send tool: Burp Repeater "Send group in parallel"
(HTTP/2 single-packet attack), Turbo Intruder (engine=Engine.BURP2, gate sync), or any
client that can flush N requests simultaneously. Two shapes:
Request A: POST /register body: csrf=<csrf>&username=hacker&email=anything@exploit.net&password=pw
Request B: GET /confirm params: token= (empty)
Fire A and B together, repeat ~20 rounds.GET /register first, then fire the batch. After it succeeds, log in as the
new account and perform the objective (e.g. a state-changing admin action such as deleting a user).
The blank-token confirm wins during the window where the user row exists but its verification
token isn't set yet.Race conditions are high-severity findings because they break financial, access control, and integrity assumptions that defenders rarely stress-test. Highest payouts come from:
Best-paying asset types: Fintech apps, SaaS platforms with credit/subscription models, social platforms with reputation systems, e-commerce checkout flows, OAuth/SSO token endpoints.
/vote, /upvote, /like, /favorite
/redeem, /apply-coupon, /use-code, /claim
/purchase, /checkout, /confirm-order, /pay
/transfer, /withdraw, /send-money
/invite, /referral, /accept-invite
/upgrade, /activate, /trial
/delete, /deactivate, /cancel
/follow, /subscribeX-RateLimit-* # rate limiting exists, but may not be atomic
X-Request-Id # each request independently tracked
No Cache-Control # stateful ops not idempotent// Single-use action buttons with client-side disable
button.disabled = true
$('#btn').prop('disabled', true)
// Optimistic UI updates (state set before server confirms)
setState({ used: true })
// Sequential async calls without locking
await useVoucher(); await deductBalance();with_lock / lock! — ActiveRecord doesn't lock by defaultSELECT ... FOR UPDATE — common in legacy codebasesINCR atomicity checksEnumerate one-time or limited-use actions — Map every endpoint that enforces a "once per user", "limited quantity", or "deduct balance" constraint. These are your primary targets.
Understand the state machine — For each target action, identify: (a) what state is read, (b) what state is written, (c) what validation sits between read and write. The gap between read and write is your window.
Capture a clean baseline request — Perform the action once legitimately with Burp Suite intercepting. Confirm you get the expected single-use behavior (e.g., coupon marked used, vote counted once).
Set up parallel request tooling — Use one of:
engine=Engine.BURP2 for last-byte synccurl with & backgroundingthreading or asyncio with pre-built connectionsExecute the race — Send 10–50 identical requests simultaneously. Key technique: pre-connect and buffer all requests, release the final byte of all simultaneously (single-packet attack when HTTP/2 is available).
Analyze responses — Look for:
200 OK where only one should succeedVerify the effect — Check the actual state: Was the credit applied twice? Did the vote count increment multiple times? Is the coupon still marked unused despite two successes?
Determine exploitability window — Re-run with decreasing parallelism (5 requests, 3 requests, 2 requests) to understand how tight the window is and reliability of exploitation.
Test across account types — Sometimes the race only works for new accounts, specific subscription tiers, or under specific server load. Test varied conditions.
Document reproducibility — Record exact timing, number of parallel requests needed, and success rate across 5 independent attempts before reporting.
# turbo_intruder_race.py
def queueRequests(target, wordlists):
engine = RequestEngine(endpoint=target.endpoint,
concurrentConnections=1,
engine=Engine.BURP2) # HTTP/2 single-packet
for i in range(20):
engine.queue(target.req, gate='race1')
engine.openGate('race1')
def handleResponse(req, interesting):
if '200' in req.status:
table.add(req)# Fire 15 simultaneous vote/redeem requests
for i in $(seq 1 15); do
curl -s -o /dev/null -w "%{http_code}\n" \
-X POST "https://target.com/api/vote" \
-H "Cookie: session=YOUR_SESSION" \
-H "Content-Type: application/json" \
-d '{"report_id": "12345", "vote": "up"}' &
done
waitimport asyncio, aiohttp
async def race_request(session, url, payload, headers):
async with session.post(url, json=payload, headers=headers) as r:
return await r.text()
async def main():
url = "https://target.com/redeem"
payload = {"code": "GIFT50"}
headers = {"Cookie": "session=XXXXX"}
async with aiohttp.ClientSession() as session:
tasks = [race_request(session, url, payload, headers) for _ in range(20)]
results = await asyncio.gather(*tasks)
for r in results:
print(r[:100]) # print first 100 chars of each response
asyncio.run(main())# Look for read-then-write without locking
grep -rn "find_by\|where.*first" --include="*.rb" | grep -v "lock"
grep -rn "SELECT.*WHERE" --include="*.php" | grep -v "FOR UPDATE"
# JavaScript async without atomicity
grep -rn "await.*get\|await.*find" --include="*.js" -A2 | grep "await.*update\|await.*save"
# Python Django ORM without select_for_update
grep -rn "\.get(\|\.filter(" --include="*.py" | grep -v "select_for_update"# Verify target supports HTTP/2 (prerequisite for single-packet attack)
curl -sI --http2 https://target.com | grep -i "HTTP/2\|h2"Check-Then-Act without atomic operations — Developer reads state (if voucher.used == false), then writes state (voucher.update(used: true)) in two separate database operations. Any thread can read the same "unused" state before either writes.
Missing database-level locking — Using ORM methods like find or filter instead of SELECT ... FOR UPDATE. The fix is one line but developers don't think about concurrency.
Optimistic concurrency without version checking — Systems increment counters or mark records without checking if the record changed since it was read.
Microservice TOCTOU — Service A validates eligibility, Service B executes the action. No shared atomic transaction spans both services.
Client-side "protection" — Developers disable the button in JavaScript after first click, assuming that prevents duplicate submissions. Server-side logic is never hardened.
Counter increments outside transactions — votes_count += 1; save() instead of an atomic SQL UPDATE SET votes = votes + 1 WHERE id = ?.
Async background jobs — Eligibility checked synchronously, fulfillment done asynchronously. A second request passes the check before the first job completes.
Caching without invalidation — Cached "has user voted?" check returns stale false during a cache miss window when the first write hasn't propagated yet.
Defense: Per-user rate limiting
Defense: Idempotency keys / unique request tokens
Defense: Database unique constraints
Defense: Short time windows / expiring tokens
Defense: Queue-based serialization
Defense: Application-layer mutex / locks
Defense: "Already used" checks in application code
UPDATE ... WHERE used=false RETURNING id truly prevents this.Before writing the report, confirm all three:
What can the attacker DO right now? Can you demonstrate — with screenshots or logs — that the same one-time action succeeded more than once? (e.g., vote count shows +2 from one user, credit balance shows double-credit, coupon shows redeemed twice)
What does the victim LOSE? Is there concrete, measurable harm? Financial loss (credits issued in excess), integrity loss (manipulated rankings/votes), or security loss (access granted beyond entitlement)? "The counter went up twice" is only valid if that counter has real-world value.
Can it be reproduced in 10 minutes from scratch? Can you write a 20-line script, run it against a fresh test account, and reliably demonstrate the duplicate effect at least 3/5 attempts? If it requires perfect timing you cannot reliably control, the exploitability claim is weak.
A bug bounty platform's "popular reports" feature allowed upvotes to improve report visibility and researcher reputation scores. By sending ~15 parallel upvote requests for the same report using a single HTTP/2 connection (single-packet attack), a researcher was able to register 10–15 votes from a single account. This allowed artificial inflation of report rankings, manipulation of researcher reputation scores, and distortion of the platform's crowdsourced prioritization system — directly undermining trust in the platform's core feature for triaging vulnerability reports.
On a major social network (Facebook-scale), promotional or limited-use actions — such as adding a phone number for a one-time security credit, or claiming a one-time bonus — were vulnerable to simultaneous parallel requests. An attacker could race the claim endpoint and receive the promotional benefit multiple times, causing direct financial loss to the platform and allowing fraudulent accumulation of platform currency or benefits at scale. Given the user volume, even a brief window before patching represented significant financial exposure.
A cloud hosting provider enforced limits on the number of resources (e.g., droplets, projects, or API keys) a free-tier user could create. The limit check and resource creation were non-atomic operations. By racing the creation endpoint with 20 simultaneous requests, an attacker bypassed the enforcement logic and created resources far exceeding their tier limit. This translated directly to unauthorized compute consumption, billing fraud, and abuse of infrastructure — impacting both the provider's revenue and system stability for legitimate users.
The following real, verified bug-bounty / coordinated-disclosure cases extend this skill. Four cases (#4, #11, #12, plus the bonus reference) use the modern HTTP/2 single-packet attack technique (Kettle DEF CON 31, 2023; Flatt Security expansion 2024) — the technique that makes most modern race exploits viable today.
GitLab — CVE-2022-4037 email-verification race (Kettle DEF CON 31 case study) (NVD · PortSwigger Research)
POST /-/profile requests changing email to two different addresses; the verification token sent to address A becomes valid for address B because state transitions weren't atomicWorldcoin (Tools for Humanity) — World ID action-verification race (Medium writeup)
canVerifyForAction appended to an array without DB-level locking; fix added nullifiers table with atomic UPSERTStripe — Promotion code redeemed past limit (H1 #1717650)
promotion_code.times_redeemedStripe — Fee discounts redeemed many times (H1 #1849626)
Reverb.com — Gift card multi-redemption (H1 #759247)
POST /gift_cards/redeem → duplicate N× → fire parallel → balance credited N× from a single cardSELECT…FOR UPDATE around the redemption readCosmos / Starport faucet — Double-mint race (H1 #1438052)
/faucet/transfer requests; the Transfer Go function executes two state-mutating actions per request, both non-atomicInnoGames — Email-activation race → unlimited diamonds (H1 #509629)
token_used flag committed → reward granted on every winning requestRyotaK / Flatt Security — "First Sequence Sync" PIN-bruteforce (10,000-req single-packet expansion) (Flatt Security Research)
POST /verify-pin requests in 166 ms, each with a different 4-6 digit guess, all landing inside the rate-limit windownopCommerce — CVE-2024-58248 gift-card double-redemption (NVD)
POST /checkout/PlaceOrder requests both applying the same gift card → both orders complete, gift card balance debited oncetriage-validation) before reporting; report via report-writing. Prefer a sandbox, disposable VM, or controlled lab.# Read-only first step; confirm scope before anything active.
cat scope.txt # target list from the authorized engagement briefAdapted from elementalsouls/Claude-BugHunter (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: executable helpers, commands, engine, and research assets not bundled.
© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/hunt-race-condition of sickn33/agentic-awesome-skills.
Open the folder on GitHubat commit b84d35a
We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
Hunt Race Condition next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hunt Race Condition this skillsickn33/agentic-awesome-skills | 47k | 1 repos | ~5.7k | Automated safety check: Pass | MIT | |
| YugabyteDB ASH Instrumentationyugabyte/yugabyte-db | 11k | — | ~4.5k | Automated safety check: Pass | Custom licence | |
| Mirage VFS Adapter Authoringstrukto-ai/mirage | 3.7k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | |
| Golang Patternsantoniopaya22/go-rest-template | 172 | 9 repos | ~3.5k | Automated safety check: Pass | None | |
| Rust Async Patternsdiodeme/Gold-Band | 143 | 10 repos | ~3.1k | Automated safety check: Pass | AGPL-3.0 | |
| Swift Concurrencyhenrypldev/react-native-nitro-mlx | 100 | 3 repos | ~3.1k | Automated safety check: Pass | MIT |
yugabyte/yugabyte-db
Procedure for adding or changing YugabyteDB Active Session History wait states in TServer and DocDB C++ code, including the macro to use for sync and async paths.
strukto-ai/mirage
Builds or extends a custom Mirage virtual filesystem adapter for an API, database, object store or app data, with a working mount configuration and filesystem tests.
antoniopaya22/go-rest-template
Idiomatic Go patterns, best practices, and conventions for building robust, efficient, and maintainable Go applications.
diodeme/Gold-Band
Master Rust async programming with Tokio, async traits, error handling, and concurrent patterns.
henrypldev/react-native-nitro-mlx
Diagnose Swift Concurrency issues, refactor callback-based code to async/await, and guide Swift 6 migration when working with tasks, actors, @MainActor, Sendable, data races, thread safety, or…
farm-fe/farm
Writes, reviews, and debugs idiomatic Rust code with memory safety and zero-cost abstractions.
sickn33/agentic-awesome-skills
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
sickn33/agentic-awesome-skills
Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.
sickn33/agentic-awesome-skills
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
sickn33/agentic-awesome-skills
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
sickn33/agentic-awesome-skills
Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.
sickn33/agentic-awesome-skills
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
Categories
Hunting skill for race condition vulnerabilities. An agent skill from sickn33/agentic-awesome-skills. Hunt Race Condition is an agent skill from sickn33/agentic-awesome-skills. Hunting skill for race condition vulnerabilities.
Hunt Race Condition fits situations like: tasks that involve Async programming.
Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-race-condition -a claude-code`. Or copy the skill folder (skills/hunt-race-condition in sickn33/agentic-awesome-skills) into .claude/skills/hunt-race-condition in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-race-condition -a codex`. Or copy the skill folder (skills/hunt-race-condition in sickn33/agentic-awesome-skills) into .agents/skills/hunt-race-condition in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill hunt-race-condition -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-race-condition, .gemini/skills/hunt-race-condition, .github/skills/hunt-race-condition and .opencode/skills/hunt-race-condition in your project.
Going by SKILL.md and its folder, Hunt Race Condition needs the command-line tools its instructions call (curl). Our summary lists: Python 3; Node.js. Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled..
SKILL.md names 6 domains. As links in the text: hackerone.com, nvd.nist.gov, portswigger.net, medium.com, flatt.tech and github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Hunt Race Condition is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.7k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Hunt Race Condition: YugabyteDB ASH Instrumentation (yugabyte/yugabyte-db, 11k stars), Mirage VFS Adapter Authoring (strukto-ai/mirage, 3.7k stars), Golang Patterns (antoniopaya22/go-rest-template, 172 stars) and Rust Async Patterns (diodeme/Gold-Band, 143 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.
Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.