No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by MyuriKanao · Claude Skill · ★ 596
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is src-hunter-skill safe to install? View the security audit →
中文 · English src-hunter 这是一个给 SRC、众测和 Bug bounty 用的 Claude Code skill。 简单说,就是你给它一个目标,它会按一套固定流程帮你推进漏洞挖掘:先确认目标范围,再做信息收集和资产枚举,然后进入漏洞测试,最后整理报告。 项目内置了一批从公开来源整理的知识库,包括: 19 类攻击 playbook 305 个结构化 payload WAF / EDR 绕过变体 HackerOne 已披露 High / Critical hacktivity 数据 WooYun 历史案例统计残余 常见国产组件指纹和默认凭据 安装 Marketplace: Git: 目录结构 playbook 是主要入口。所有 playbook 都按黑盒视角编写,默认你只有 URL,没有源码。 每个 playbook 都围绕同一套问题展开: 去哪里找入口 用什么 payload 测 观察哪些响应特征 如何判断影响 如何提高漏洞价值 哪些行为不能做 整体思路不是堆 payload,而是把测试动作、证据留存和报告输出串起来。 MCP 工具集成 本 skill 集成本地 MCP 服务器作为工具层,让 Claude 在 hunt 阶段能直接调用浏览器自动化、CDP 调试、网络拦截、JS hook、AST 反混淆、Frida 内存验证、WASM 逆向、Source map 重构、Android adb 桥接、SSL pinning 绕过等能力。 当前主选:jshookmcp 0.3.0(134 工具精选 / 386 全集 / 36 域),完整索引与场景映射见 。 7 个高关联 playbook( /
| Stars | 596 |
| Forks | 80 |
| Category | Claude Skill |
| License | MIT |
| Quality Score | 60.7781210999229/100 |
| Open Issues | 3 |
| Last Updated | 2026-05-24 |
| Created | 2026-05-09 |
| Platforms | claude-code |
| Est. Tokens | ~1042k |
These tools work well together with src-hunter-skill for enhanced workflows:
Looking for a src-hunter-skill alternative? If you're comparing src-hunter-skill with other claude skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized pene
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models,
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a
Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents
MCP server that connects AI assistants to HackerOne for bug bounty hunting
AI Powered penetration testing Platform for offensive security research
Explore other popular claude skill tools:
src-hunter-skill is 实战 SRC / 众测 / Bug bounty 漏洞挖掘 Claude Code skill — 19 个攻击类 playbook、305 个结构化 payload、263 个 WAF/EDR 绕过、2887 份 HackerOne 真实案例、88,636 WooYun 案例统计. It is categorized as a Claude Skill with 596 GitHub stars.
You can find installation instructions and usage details in the src-hunter-skill GitHub repository at github.com/MyuriKanao/src-hunter-skill. The project has 596 stars and 80 forks, indicating an active community.
src-hunter-skill is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to src-hunter-skill on Agent Skills Hub include pentest-ai-agents, CyberStrike, pentest-ai. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: