hunt-exceptional-conditions
Hunt mishandling of exceptional conditions — feed an endpoint malformed/unexpected input (wrong type, broken JSON, oversized field, null byte) and make it fail OPEN or leak internals: a verbose stack-trace / framework error page that discloses ORM internals, server file paths, library versions, or a…
Install / Use
npx skills add elementalsouls/Claude-BugHunter --skill hunt-exceptional-conditionsInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of hunt-exceptional-conditions
hunt-exceptional-conditions scores 87/100 on our quality scale, 853rd of 3,055 Development & Engineering skills we index (top 28%).
Its SKILL.md is 3.1 KB long, split into 6 sections with 2 code examples: a solid amount of guidance for an agent.
With 4,669 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 2 days ago, so hunt-exceptional-conditions is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-09-28. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
hunt-exceptional-conditions compared with similar skills
All 4 of these similar skills score higher than hunt-exceptional-conditions; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hunt-exceptional-conditions (this skill)by elementalsouls | 87 | 4.7k | 2d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 85.9k | 12d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.0k | 1d ago | CLAUDE.md |
| ai-job-searchby MadsLorentzen | 100 | 44.3k | today | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | 2d ago | CLAUDE.md |
Frequently asked questions
- How do I install hunt-exceptional-conditions?
- Run
npx skills add elementalsouls/Claude-BugHunter --skill hunt-exceptional-conditions. The install tabs above show the steps for each supported agent. - Which AI agents does hunt-exceptional-conditions work with?
- It is written for Zed, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is hunt-exceptional-conditions safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hunt-exceptional-conditions still maintained?
- The repository was last updated 2 days ago, so hunt-exceptional-conditions is actively maintained.
Skill content
View source on GitHubname: hunt-exceptional-conditions description: "Hunt mishandling of exceptional conditions — feed an endpoint malformed/unexpected input (wrong type, broken JSON, oversized field, null byte) and make it fail OPEN or leak internals: a verbose stack-trace / framework error page that discloses ORM internals, server file paths, library versions, or a language traceback. Use on any input-accepting endpoint (JSON APIs, forms, query params). Medium-High when the leak exposes internal structure that arms a deeper attack." report_count: 0 sources: hackerone_public
HUNT-EXCEPTIONAL-CONDITIONS — Verbose Errors / Fail-Open (A10:2025)
What actually pays
Well-built apps catch errors and return a clean, generic message. A broken app, when handed input it didn't expect, throws an unhandled exception and renders a developer error page straight to the client — leaking the stack trace, the ORM/query internals, server-side file paths, and framework/library versions. That disclosure is the finding (and it arms SQLi/RCE/path attacks next).
Recon
Any endpoint that parses input is a candidate; the richest are:
JSON APIs that expect typed fields: POST /api/* with {numbers, ids, enums}
Endpoints with numeric/id path or query params: /item/{id}, ?page=, ?quantity=
Search / filter / sort params
File or content-type sensitive uploads
Attack — send what the code didn't anticipate
Take a known-good request and break ONE assumption at a time:
- Wrong type: a field the app expects to be a number/string is sent as an
array or object —
{"rating":"x","comment":[1,2,3]},{"quantity":{}}. - Malformed body: truncated/!invalid JSON, an unterminated string, a stray brace, a wrong/missing Content-Type.
- Boundary/oversized: a very long string, a huge/negative/overflow number.
- Null byte / control chars embedded in a value.
POST /api/Feedbacks {"rating":"notanumber","comment":[1,2,3]}
GET /item/' OR /item/%00 (also exercises the error path)
Watch the RESPONSE BODY, not just the status: a 500 (or even a 200/400) whose body contains a stack trace or framework error page is the signal.
What counts as a leak (the success signal)
A finding is confirmed when the response body contains a cross-framework error-disclosure signature:
- Node/Express + Sequelize:
SequelizeDatabaseError,node_modules/sequelize, a JS stack with internal paths. - PHP:
<b>Warning</b> ... /var/www/.../file.php on line N. - Python:
Traceback (most recent call last),werkzeug.exceptions. - Java:
at com.app.Foo(Foo.java:42)stack frames. - .NET:
Server Error in '/' Application, a[System.XxxException: ...]YSOD.
A clean JSON error ({"error":"Invalid input"}) with no internals is NOT a
finding — that's correct handling. Disclosure of internal structure is.
Validation discipline
- Capture the exact leaked artifact (path, ORM class, version, stack frame) — that's the evidence. "It returned 500" alone is not disclosure.
- Note what the leak enables next (e.g. a disclosed SQL error → hunt-sqli; a disclosed absolute path → hunt-lfi).
Related Skills
Agent-Reach
85.9kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.0kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ai-job-search
44.3kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
