Install any skill in seconds. Free to start, no credit card required.
Get Started Free →1. Read program scope, policy, safe harbor
.claude/skills/hunting-methodology/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-10 | ✗→✓ | ▲ Improved | — | — |
| case-16 | ✗→✓ | ▲ Improved | — | — |
| case-19 | ✗→✓ | ▲ Improved | — | — |
| case-03 | ✗→✓ | ▲ Improved | — | — |
| case-20 | ✗→✓ | ▲ Improved | — | — |
/surface for P1/P2/Kill rankingentrypoint × method × content-type × encoding × bypassuv run python3 $CLAUDE_PROJECT_DIR/tools/intel_engine.py matrix <class>)html-entity+URL(%26lt%3Bscript%26gt%3B), URL+html-entity, unicode-escape+URL, base64+URL. WAFs typically decode once; targets decode twice, so a payload that looks benign after a single decode still executes at the sink.
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> recon "coverage-<class>" "<details>" so autopilot resume avoids repeating exhausted paths.Wide route (recon-heavy): New target, unknown surface, no prior data.
/pipeline for broad coverage first/surface to prioritizeDeep route (hunt-heavy): Known target, mapped surface, returning hunter.
/resume to see what's untestedDevelopers make CLASS mistakes, not random ones:
| Rule | Action | |---|---| | 5-minute rule | No interesting signals after 5 min → skip target | | 20-minute rotation | No progress in 20 min → rotate vuln class or endpoint | | 1-hour rule | Stuck on one target for 1 hour → switch programs entirely | | A→B time box | 20 min per B candidate, max 3 candidates | | Exhaustion rule | A class is "exhausted" only after the depth matrix baseline + sibling coverage (see Phase 3 steps 6-11) |
| Bug Class | Competition | Avg Payout | Verdict | |---|---|---|---| | IDOR | Medium | High | Best ROI — always test first | | Auth bypass | Medium | High | Second priority | | Business logic | Low | High | Unique to each target | | Race conditions | Low | Medium-High | Under-tested | | OAuth/OIDC chains | Low | High | Complex but high payoff | | SSRF → cloud | Medium | Very High | If you find DNS callback | | Cache poisoning | Low | High | Rare skill | | XSS | Very High | Medium | Skip unless you have a chain | | Open redirect | Very High | Low | Only with OAuth chain | | Missing headers | Infinite | $0 | Never submit |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-09 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-10 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-16 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-18 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-19 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-21 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-03 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-04 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-20 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-01 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-12 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-13 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-17 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-22 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-11 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-06 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-15 | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-05 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-08 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-02 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-14 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-07 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +50 percentage points is the difference between those two pass rates over the 22 comparable cases. 2 cases got worse with the skill loaded, and they are included in that figure.
The per-case answers from this run were removed by the retention sweep, so the case table below shows the verdicts without the text either arm produced. The counts above were recorded at the time and are unaffected. Answers are now kept for 180 days.
Other measured skills in the registry, with their headline benchmark lift.