Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Check if a vulnerability has already been reported. Searches platform hacktivity + local findings. Usage: /dupcheck <vuln_type> e.g. /dupcheck XSS in search endpoint
.claude/skills/h-mmer-dupcheck/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-08 | ✗→✓ | ▲ Improved | -19% | 0% |
| case-10 | ✗→✓ | ▲ Improved | -31% | 0% |
| case-11 | ✗→✓ | ▲ Improved | -11% | 0% |
| case-12 | ✗→✓ | ▲ Improved | -19% | 0% |
| case-18 | ✗→✓ | ▲ Improved | -7% | 0% |
Check for duplicate reports: $ARGUMENTS
scope.yaml in the current directory.bounty-platforms MCP tool search_hacktivity with platform, program, and "$ARGUMENTS" as the query.uv run python3 ../../tools/dedup_findings.py --stats --db findings.jsonhacktivity.md if it exists and grep for related terms.After checking local findings, also search the writeup database:
search_writeups MCP tool with "<finding description> <target>"Duplicate risk is about overlap of exploit primitive and affected asset, not keyword similarity.
Report four verdict fields:
same_asset_same_primitive: likely duplicate unless your impact is strictly strongersame_primitive_different_asset: possible duplicate; explain scope difference and noveltysame_asset_different_primitive: usually unique; prove a different root causeknown_class_new_chain: often worth reporting if the chain reaches a new impact tierCheck disclosed writeups for patch language and response tone. If triagers historically close this class as N/A, require chain proof before submission. If public reports stop at a weaker impact, frame your report around the new capability, not the shared first step.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-05 | fail→fail | 10,191 | 5,592 | -45% | 1 | 1 | 0% | 2,147 | 709 | -67% | 0 | 0 | — |
case-06 | fail→fail | 11,354 | 5,350 | -53% | 1 | 1 | 0% | 1,764 | 782 | -56% | 0 | 0 | — |
case-07 | pass→fail | 22,554 | 17,842 | -21% | 1 | 1 | 0% | 3,746 | 793 | -79% | 0 | 0 | — |
case-08 | fail→pass | 7,946 | 4,039 | -49% | 1 | 1 | 0% | 1,409 | 1,142 | -19% | 0 | 0 | — |
case-01 | fail→fail | 13,675 | 5,218 | -62% | 1 | 1 | 0% | 2,149 | 751 | -65% | 0 | 0 | — |
case-02 | fail→fail | 17,002 | 31,864 | +87% | 1 | 1 | 0% | 1,700 | 1,963 | +15% | 0 | 0 | — |
case-03 | fail→fail | 17,672 | 21,536 | +22% | 1 | 1 | 0% | 1,696 | 2,937 | +73% | 0 | 0 | — |
case-04 | fail→fail | 14,187 | 11,075 | -22% | 1 | 1 | 0% | 1,707 | 1,914 | +12% | 0 | 0 | — |
case-09 | fail→fail | 13,596 | 19,484 | +43% | 1 | 1 | 0% | 2,267 | 636 | -72% | 0 | 0 | — |
case-10 | fail→pass | 11,554 | 6,156 | -47% | 1 | 1 | 0% | 1,958 | 1,346 | -31% | 0 | 0 | — |
case-11 | fail→pass | 11,692 | 6,747 | -42% | 1 | 1 | 0% | 1,853 | 1,640 | -11% | 0 | 0 | — |
case-12 | fail→pass | 7,868 | 3,911 | -50% | 1 | 1 | 0% | 1,369 | 1,109 | -19% | 0 | 0 | — |
case-13 | pass→pass | 15,473 | 24,313 | +57% | 1 | 1 | 0% | 1,801 | 2,463 | +37% | 0 | 0 | — |
case-14 | fail→fail | 13,356 | 8,194 | -39% | 1 | 1 | 0% | 2,291 | 683 | -70% | 0 | 0 | — |
case-15 | fail→fail | 10,371 | 12,495 | +20% | 1 | 1 | 0% | 1,736 | 638 | -63% | 0 | 0 | — |
case-16 | fail→fail | 10,007 | 3,384 | -66% | 1 | 1 | 0% | 1,636 | 663 | -59% | 0 | 0 | — |
case-17 | pass→fail | 10,773 | 5,882 | -45% | 1 | 1 | 0% | 1,709 | 852 | -50% | 0 | 0 | — |
case-18 | fail→pass | 12,512 | 8,096 | -35% | 1 | 1 | 0% | 1,813 | 1,686 | -7% | 0 | 0 | — |
case-19 | fail→pass | 5,441 | 2,897 | -47% | 1 | 1 | 0% | 946 | 767 | -19% | 0 | 0 | — |
case-20 | pass→pass | 9,130 | 9,502 | +4% | 1 | 1 | 0% | 1,912 | 2,318 | +21% | 0 | 0 | — |
case-21 | pass→pass | 14,777 | 15,113 | +2% | 1 | 1 | 0% | 2,811 | 3,322 | +18% | 0 | 0 | — |
case-22 | pass→pass | 10,366 | 6,894 | -33% | 1 | 1 | 0% | 1,831 | 1,595 | -13% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 14 counted toward the lift figure. The other 8 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +18 percentage points is the difference between those two pass rates over the 14 comparable cases. 3 cases got worse with the skill loaded, and they are included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.