Agent skill

Mock Hunter

by sickn33 in sickn33/agentic-awesome-skills

Audit a live web page in five phases (catalog, click, trace, classify, report) to identify mock data, hardcoded values, LLM-generated metrics, and broken endpoints.

MITAuto-check passedProductivity & Automation

Install Mock Hunter

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill mock-hunter -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills mock-hunter --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mock-hunter .claude/skills/mock-hunter && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mock-hunter
GitHub stars
47k
Used in
1 other repo
Token cost
~1.9k tokens
SKILL.md length
745 words
Files
1
Skills in repo
1,493
Repo updated
First seen
Licence
MIT

At a glance

Audit a live web page in five phases (catalog, click, trace, classify, report) to identify mock data, hardcoded values, LLM-generated metrics, and broken endpoints.

  • Works in 5 steps: Setup & Smart Questions → Navigate & Catalog → Test Interactivity → …
  • Tasks that involve Web search
  • SKILL.md covers Overview, When to Use This Skill, How It Works and Examples, plus 3 more sections
  • Reaches example-saas.com

What it does

Mock Hunter is an agent skill from sickn33/agentic-awesome-skills. Audit a live web page in five phases (catalog, click, trace, classify, report) to identify mock data, hardcoded values, LLM-generated metrics, and broken endpoints. Outputs a markdown report with REAL/MOCK/LLM/HARDCODED/BROKEN/UNKNOWN verdicts per visible value.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation, covering Web search. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Web search

Example prompts

  • “/mock-hunter”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Setup & Smart Questions
  2. Navigate & Catalog
  3. Test Interactivity
  4. Trace Provenance
  5. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 680176d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • example-saas.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mock Hunter loads about 1.9k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 745 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 680176d, republished under its MIT licence (© sickn33). 745 words, ~1,877 tokens.

Download SKILL.mdSave it as .claude/skills/mock-hunter/SKILL.md (or your agent's skills folder).
name
mock-hunter
description
Audit a live web page in five phases (catalog, click, trace, classify, report) to identify mock data, hardcoded values, LLM-generated metrics, and broken endpoints. Outputs a markdown report with REAL/MOCK/LLM/HARDCODED/BROKEN/UNKNOWN verdicts per visible value.
category
testing
risk
critical
source
community
source_repo
CodeShuX/mockhunter
source_type
community
date_added
2026-05-07
author
CodeShuX
tags
testing, qa, playwright, mock-detection, web-audit, ai-testing, vibe-coding, claude-code
tools
claude
license
MIT

MockHunter — Live Page Reality Check

Overview

MockHunter is a Claude Code skill that audits a live web page and tells you, for every visible value, whether it is real, mocked, LLM-generated, hardcoded, broken, or unknown. It is built for vibe-coded apps (Lovable, Bolt, v0, Replit, AI Studio, Cursor Composer) where the UI may look complete but the data layer often is not. It uses Playwright MCP to drive a real browser, then traces each visible value through the network and DOM to its source.

This skill adapts the upstream CodeShuX/mockhunter project (community source).

Because this workflow drives a real browser against live pages, treat it as an interactive audit tool, not a plugin-safe read-only helper. Default to observation-only until the user confirms the target is theirs, identifies a safe test account or environment, and explicitly approves any click, submit, or authenticated action that can mutate state.

When to Use This Skill

  • Use when auditing an AI-generated UI to find out which values are actually wired up
  • Use when reviewing a contractor or teammate's deliverable before sign-off
  • Use before showing a vibe-coded MVP to a customer or investor
  • Use when a dashboard "looks too clean" — every metric uniformly round, all timestamps clustered, no variance — and you suspect seeded data

How It Works

Phase 1: Setup & Smart Questions
  1. Greet the user, ask for the target URL
  2. Auto-detect the stack from the URL (*.lovable.app, *.bolt.new, *.v0.app, *.replit.app, aistudio.google.com, otherwise Custom)
  3. Ask 3-5 targeted questions: auth mode (public / localhost / form / skip), DB access (optional), suspicions, page goal
  4. Confirm the audit plan, ownership/permission, target environment, and allowed action classes before proceeding
Phase 2: Navigate & Catalog
  1. browser_navigate to the target URL
  2. Handle auth per chosen mode (form-login: fill fields, click submit)
  3. Wait for network idle (max 10s)
  4. Take full-page screenshot, capture accessibility snapshot
  5. Inventory every: heading, button, link, input, card, badge, stat, table cell, empty state, image
  6. Capture initial console errors and network requests
Phase 3: Test Interactivity
  1. For every tab: click only after the user has approved navigation-style interactions, then snapshot, scroll to bottom, re-catalog
  2. For every button: click only user-approved, allowlisted controls that are clearly non-destructive by role, accessible name, nearby text, icon, URL/action target, and expected network side effect; skip destructive or ambiguous controls rather than relying on a label regex alone
  3. For every form: identify required fields and prefer empty-submit validation; submit throwaway data only when the user explicitly approved the exact form, target environment, and test account
  4. Record per-element behavior
Phase 4: Trace Provenance

For every visible value, run this decision tree:

Did any network request return this value?
├── YES — found in a response:
│   ├── Status 4xx/5xx → BROKEN
│   ├── Endpoint matches /ai|openai|generate|llm|chat → LLM
│   ├── Response shape matches mock library (faker, MSW, mockoon) → MOCK
│   ├── Uniformity flags trigger → MOCK or LLM (review)
│   ├── DB connection provided?
│   │   ├── Run read-only SELECT, value matches DB row → REAL
│   │   └── Value not in DB → MOCK
│   └── No DB → UNKNOWN (best-guess)
└── NO — value not in any network response:
    ├── String literal in DOM source → HARDCODED
    ├── Computed from Math.random / Date.now / faker → MOCK
    └── Cannot determine → UNKNOWN

Uniformity heuristics flag suspicious data:

  • All numeric values identical across rows
  • All percentages round (50%, 75%, 90%)
  • All timestamps cluster within a single minute
  • < 3 unique values across 10+ rows
Show full SKILL.md (280 more words)Show less
Phase 5: Report

Generate mockhunter-report.md with:

  • Summary table (verdict counts)
  • Findings per section/tab (element / value / verdict / source / severity / action)
  • Console errors and network failures
  • NO-OP buttons
  • Suspicious patterns
  • Smart follow-up questions for the user

Examples

Example 1: Auditing a Lovable admin dashboard
User: /mockhunter audit https://my-app.lovable.app/admin
Skill: [Phase 1] Stack detected: Lovable. Auth: skip. DB: no.
       [Phase 2] Catalog: 6 stat cards, 4 verification queues, 8 activity items.
       [Phase 3] Search box: NO-OP (zero network requests). Activity link → 404.
       [Phase 4] Bundle 2.7 MB. Zero /api/, zero supabase, zero axios.
                 "$42,850" → string literal in JSX → HARDCODED.
                 "+12% vs last month" → string literal → HARDCODED.
       [Phase 5] Verdict: 23 HARDCODED, 1 BROKEN, 1 NO-OP, 0 REAL.
                 Report written to ./mockhunter-report.md
Example 2: Public marketing site (mostly real)
User: /mockhunter audit https://example-saas.com
Skill: ...
       [Phase 5] Verdict: 8 REAL, 18 HARDCODED (intentional marketing copy),
                 0 MOCK, 0 BROKEN, 2 UNKNOWN.
                 No console errors, no broken endpoints.

Best Practices

  • ✅ Provide DB access when available — lifts UNKNOWN verdicts to REAL or MOCK
  • ✅ Use a dedicated test account for form-login auth
  • ✅ Run cold-start tests (zero data) — many vibe-coded apps fail there
  • ✅ Tell the skill if specific sections are intentionally AI-generated, so it doesn't false-flag them
  • ❌ Don't run active interaction on apps you don't own without permission — live clicks and form submissions can mutate state
  • ❌ Don't trust a destructive-button exclusion list by itself — localized labels, icons, aria text, and backend routes can hide mutating actions
  • ❌ Don't trust the audit if the page failed to load — check console first

Limitations

  • Single-page audit per run — no multi-page crawl in v0.1.0
  • Form-login only for auth — no OAuth, magic-link, or 2FA in v0.1.0
  • Caps at ~30 most-prominent buttons per page
  • Markdown report only — no JSON output yet
  • DB verification supports any DB reachable via shell command (psql, mysql, mongosh, wrangler, supabase REST), but not Firestore directly

Security & Safety Notes

  • The skill runs read-only DB SELECTs only, never INSERT/UPDATE/DELETE
  • Skips destructive-looking, ambiguous, icon-only, localized, or external-write controls unless the user has explicitly allowlisted the exact control and environment
  • Never submits forms that look like payment, account deletion, external write operations, account changes, invites, publishing, deployment, messaging, or money movement
  • Uses placeholder credentials (mockhunter@example.com) for any throwaway form tests, never the user's real credentials
  • All Playwright actions happen in a controlled MCP browser context — no headless escalation

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/mock-hunter of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 680176d

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Mock Hunter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mock Hunter compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mock Hunter this skillsickn33/agentic-awesome-skills47k1 repos~1.9kAutomated safety check: PassMIT
Brave Searchbadlogic/pi-skills2.6k5 repos~592Automated safety check: PassMIT
Enterprise AI Scenario MapMetaInFLow/Enterprise-ai-scenario-map-skill632—~1.8kAutomated safety check: PassMIT
Web Searchjjyaoao/HelloAgents3.2k1 repos~5.6kAutomated safety check: PassMIT
Ddg SearchTheSyart/claude-agent-examples4051 repos~493Automated safety check: PassNone
Local Web SearchuluckyXH/OpenMOSS1.3k—~392Automated safety check: NotesMIT

Similar skills

  • Brave Search

    badlogic/pi-skills

    Web search and content extraction via Brave Search API. An agent skill from badlogic/pi-skills.

    2.6k GitHub starsUsed in 5 repos~592 tokens
    Productivity & AutomationAuto-check passed
  • Enterprise AI Scenario Map

    MetaInFLow/Enterprise-ai-scenario-map-skill

    企业AI场景地图生成报告工具。通过 web-search 深度调研企业信息,按照V2.1标准模板生成结构化AI应用场景地图报告,包含企业画像、业务诊断、行业实践、AI场景全量表、实施路径等完整内容。

    632 GitHub stars~1.8k tokensUpdated 6 mo ago
    Productivity & AutomationAuto-check passed
  • Web Search

    jjyaoao/HelloAgents

    Implement web search capabilities using the z-ai-web-dev-sdk.

    3.2k GitHub starsUsed in 1 repo~5.6k tokens
    Productivity & AutomationAuto-check passed
  • Ddg Search

    TheSyart/claude-agent-examples

    Web search without an API key using DuckDuckGo Lite via webfetch.

    405 GitHub starsUsed in 1 repo~493 tokens
    Productivity & AutomationAuto-check passed
  • Local Web Search

    uluckyXH/OpenMOSS

    A skill your agent uses when the user asks for web search that should run via the local-160 Responses API with websearch tool (base URL like https://proxy.example.com, model gpt-5.2-codex(xhigh)).

    1.3k GitHub stars~392 tokensUpdated 3 mo ago
    Productivity & AutomationAuto-check: notes
  • Ask Search

    ythx-101/ask-search

    Web search via self-hosted SearxNG. An agent skill from ythx-101/ask-search.

    537 GitHub stars~332 tokensUpdated 6 mo ago
    Productivity & AutomationAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,493 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about Mock Hunter

What does Mock Hunter do?

Audit a live web page in five phases (catalog, click, trace, classify, report) to identify mock data, hardcoded values, LLM-generated metrics, and broken endpoints. Mock Hunter is an agent skill from sickn33/agentic-awesome-skills. Audit a live web page in five phases (catalog, click, trace, classify, report) to identify mock data, hardcoded values, LLM-generated metrics, and broken endpoints.

When should I use Mock Hunter?

Mock Hunter fits situations like: tasks that involve Web search.

How do I install Mock Hunter in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill mock-hunter -a claude-code`. Or copy the skill folder (skills/mock-hunter in sickn33/agentic-awesome-skills) into .claude/skills/mock-hunter in your project. Claude Code loads it when a task matches its description.

How do I install Mock Hunter in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill mock-hunter -a codex`. Or copy the skill folder (skills/mock-hunter in sickn33/agentic-awesome-skills) into .agents/skills/mock-hunter in your project. Codex loads it when a task matches its description.

Can I use Mock Hunter in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill mock-hunter -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mock-hunter, .gemini/skills/mock-hunter, .github/skills/mock-hunter and .opencode/skills/mock-hunter in your project.

What does Mock Hunter need to run?

SKILL.md names no scripts, command-line tools or credentials: Mock Hunter is instructions for the agent only.

Does Mock Hunter access the network?

SKILL.md names 1 domain. In commands or code: example-saas.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Mock Hunter safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mock Hunter use?

Mock Hunter is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mock Hunter use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Mock Hunter?

Skills that share tags, products or a category with Mock Hunter: Brave Search (badlogic/pi-skills, 2.6k stars), Enterprise AI Scenario Map (MetaInFLow/Enterprise-ai-scenario-map-skill, 632 stars), Web Search (jjyaoao/HelloAgents, 3.2k stars) and Ddg Search (TheSyart/claude-agent-examples, 405 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mock Hunter?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,379 GitHub stars. The repository holds 1,493 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.