Screened · automated checks passed
hunt-nodejs
What the author says it does
Hunt Node.js specific vulnerabilities — Prototype Pollution → RCE chains (lodash/merge/assign), Express trust proxy misconfiguration, child_process/eval injection, template engine SSTI (EJS/Pug/Handlebars), path traversal in file servers, require() injection, environment variable exfil via /proc/self/environ. Use when target runs Node.js/Express/Fastify/NestJS/Koa.
Quoted from the skill's own SKILL.md trigger description — this is what tells
Claude when to activate it. Not yet verified by us.
Automated screening
100/100 validator score
Scored by the same rules as our free SKILL.md validator: trigger description quality, body substance, structure. Automated — a human bench test is the next step in the pipeline.
Install (unverified — review first)
git clone https://github.com/elementalsouls/Claude-BugHunter # skill lives at: skills/hunt-nodejs/SKILL.md
SkillProof status
This skill is in our test queue. We install every skill in a clean environment, run a trigger battery and score output against a baseline before it earns a catalog page — the full protocol is public. Until then, treat it like any unreviewed dependency: read the SKILL.md and any scripts before installing.
Already tested in Productivity & Workflow
- Fetch URL As Markdown Local trafilatura-first URL-to-Markdown fetcher with a clean exit-code contract for when to fall back to Exa.
- Refresh Context Map Rebuilds the AIDEV-anchor/AGENTS.md/ADR manifest that powers claude-leverage's PreToolUse context hook.
- Video Vision Local ffmpeg+Whisper pipeline that lets Claude actually watch and transcribe video files
- YT Digest Turns a YouTube URL into a timestamped, screenshotted markdown research note via real yt-dlp + ffmpeg.