ZBS Index What actually exists in applied AI, with the source next to it

skill

hunt-cloud-misconfig

Hunt cloud / infrastructure misconfigurations. AWS: public S3 buckets (s3:GetObject anonymous), permissive bucket policies (PutObjectAcl public-write), exposed CloudFront origin, public Lambda function URL, public RDS snapshot, IAM credentials in JS bundles, AWS metadata accessible via SSRF. GCP: public GCS buckets, exposed Cloud Run services, leaked service account JSON. Azure: public blob containers, exposed Function App. (Kubernetes/Docker exposure is owned by hunt-k8s; CI/CD pipeline attacks by hunt-cicd; post-credential IAM escalation by cloud-iam-deep.) Detection: targeted dorking, certificate transparency, JS bundle secret extraction, port scan for known service ports. Validate: actual data read / write / RCE. Use when hunting cloud-native storage and compute misconfig (S3/GCS/Blob, IMDS-via-SSRF, serverless, public managed services).

Description as published by the maintainer. Source

  • active

active — Most recent push to the repository was 2026-08-03.

Signals

These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.

Signal Value What it measures Window Observed Source
GitHub stars 3,319 Stars on the repository that contains this skill, not on the skill itself. A collection of fifty skills shares one number, so it says nothing about this particular skill. cumulative, all time GitHub
Last commit 2026-08-03 Most recent push to the containing repository. It may reflect work on a different skill in the same collection. point in time GitHub
repository status active The repository holding this skill exists and is not archived. as of fetch GitHub

Will this work with your setup?

Install location suggests this is meant for claude-code. The author tagged this repository "claude-skills" on GitHub. That is their statement of intent, not a test result.

We have not run this skill against a task with and without it enabled, so we cannot tell you whether it improves anything, what it costs in tokens, or whether it duplicates behaviour your harness already has. When we have run that test, the result will appear on this page with the task, the versions and the budget it used.

The skill definition lives at skills/hunt-cloud-misconfig/SKILL.md in https://github.com/elementalsouls/Claude-BugHunter.

Where to get it

Related, by what their authors tagged them

  • elementalsouls-claude-bughunter-apk-redteam-pipeline — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx…
  • elementalsouls-claude-bughunter-bb-local-toolkit — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Local-tooling companion to the bug-bounty orchestrator — carries the SAME complete bug-bounty workflow, but reach for T…
  • elementalsouls-claude-bughunter-bb-methodology — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next.…
  • elementalsouls-claude-bughunter-bug-bounty — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source c…
  • elementalsouls-claude-bughunter-bugcrowd-reporting — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exa…
  • elementalsouls-claude-bughunter-cloud-iam-deep — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-dis…
  • elementalsouls-claude-bughunter-enterprise-vpn-attack — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    External SSL VPN / remote-access appliance attack matrix — Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix Net…
  • elementalsouls-claude-bughunter-evidence-hygiene — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Evidence-capture and PoC-redaction discipline for bug-bounty submissions: cookie redaction protocol (which fields to ma…
  • elementalsouls-claude-bughunter-hunt-api-misconfig — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering. Mass assignment: send {…
  • elementalsouls-claude-bughunter-hunt-aspnet — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Hunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encrypted), machineKey recovery, dual-parser…

These share tags the maintainers applied themselves, such as ai-security, application-security, bug-bounty, bugbounty. Common tags like "mcp" or "ai" are ignored for this: agreeing with six hundred other projects is not a similarity.

This is not a recommendation and not a test result. It is a map of what the authors said their work is about.

Also from elementalsouls

How the author describes it

Topics the maintainer set on GitHub: ai-security, anthropic, application-security, bug-bounty, bugbounty, bugcrowd, claude, claude-code, claude-skills, ethical-hacking, hackerone, offensive-security, pentesting, red-team, security-tools, web-security.

Bring your own setup

We take apart real AI setups every week and show what broke, what cost too much, and what the trace actually said. If you run agents on real work, that is where the useful conversation is.

Join ZBS AI Practice Lab

Sources

  1. elementalsouls/Claude-BugHunter on GitHub — GitHub, observed , trust tier 3.