src-hunter-skill — security grade SAFE, quality 61/100

Security audit verdict: SAFE · quality 61/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by MyuriKanao · Claude Skill · ★ 596

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is src-hunter-skill safe to install? View the security audit →

About src-hunter-skill

中文 · English src-hunter 这是一个给 SRC、众测和 Bug bounty 用的 Claude Code skill。 简单说,就是你给它一个目标,它会按一套固定流程帮你推进漏洞挖掘:先确认目标范围,再做信息收集和资产枚举,然后进入漏洞测试,最后整理报告。 项目内置了一批从公开来源整理的知识库,包括: 19 类攻击 playbook 305 个结构化 payload WAF / EDR 绕过变体 HackerOne 已披露 High / Critical hacktivity 数据 WooYun 历史案例统计残余 常见国产组件指纹和默认凭据 安装 Marketplace: Git: 目录结构 playbook 是主要入口。所有 playbook 都按黑盒视角编写,默认你只有 URL,没有源码。 每个 playbook 都围绕同一套问题展开: 去哪里找入口 用什么 payload 测 观察哪些响应特征 如何判断影响 如何提高漏洞价值 哪些行为不能做 整体思路不是堆 payload,而是把测试动作、证据留存和报告输出串起来。 MCP 工具集成 本 skill 集成本地 MCP 服务器作为工具层,让 Claude 在 hunt 阶段能直接调用浏览器自动化、CDP 调试、网络拦截、JS hook、AST 反混淆、Frida 内存验证、WASM 逆向、Source map 重构、Android adb 桥接、SSL pinning 绕过等能力。 当前主选:jshookmcp 0.3.0(134 工具精选 / 386 全集 / 36 域),完整索引与场景映射见 。 7 个高关联 playbook( /

bug-bountyclaude-codeclaude-code-skillhackeroneowasppayloadspentestingred-teamsecuritysrc

Quick Facts

Stars596
Forks80
CategoryClaude Skill
LicenseMIT
Quality Score60.7781210999229/100
Open Issues3
Last Updated2026-05-24
Created2026-05-09
Platformsclaude-code
Est. Tokens~1042k

Compatible Skills

These tools work well together with src-hunter-skill for enhanced workflows:

  • h1-brain — semantic(0.58)+complementary+rare_topics+shared_platform (59%)
  • claude-bug-bounty — semantic(0.47)+complementary+rare_topics+shared_platform (55%)
  • pentest-agents — semantic(0.45)+complementary+rare_topics+shared_platform (55%)

src-hunter-skill alternative? Top 6 similar tools

Looking for a src-hunter-skill alternative? If you're comparing src-hunter-skill with other claude skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • pentest-ai-agents by 0xSteph · ⭐ 2.1k

    Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized pene

  • CyberStrike by CyberStrikeus · ⭐ 1.9k

    Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models,

  • pentest-ai by 0xSteph · ⭐ 1.7k

    Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a

  • pentest-agents by H-mmer · ⭐ 794

    Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents

  • h1-brain by PatrikFehrenbach · ⭐ 333

    MCP server that connects AI assistants to HackerOne for bug bounty hunting

  • nyxstrike by CommonHuman-Lab · ⭐ 145

    AI Powered penetration testing Platform for offensive security research

More Claude Skill Tools

Explore other popular claude skill tools:

View all Claude Skill tools →

Frequently Asked Questions

What is src-hunter-skill?

src-hunter-skill is 实战 SRC / 众测 / Bug bounty 漏洞挖掘 Claude Code skill — 19 个攻击类 playbook、305 个结构化 payload、263 个 WAF/EDR 绕过、2887 份 HackerOne 真实案例、88,636 WooYun 案例统计. It is categorized as a Claude Skill with 596 GitHub stars.

How do I install or use src-hunter-skill?

You can find installation instructions and usage details in the src-hunter-skill GitHub repository at github.com/MyuriKanao/src-hunter-skill. The project has 596 stars and 80 forks, indicating an active community.

What license does src-hunter-skill use?

src-hunter-skill is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to src-hunter-skill?

The top alternatives to src-hunter-skill on Agent Skills Hub include pentest-ai-agents, CyberStrike, pentest-ai. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Claude Skill tools