hunt-information-disclosure
Hunt error leakage, DVCS exposure, source maps, config files, and differential oracles.
Install / Use
npx skills add uphiago/recon-skills --skill hunt-information-disclosureInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of hunt-information-disclosure
hunt-information-disclosure scores 89/100 on our quality scale, 1201st of 4,259 Development & Engineering skills we index (top 29%).
Its SKILL.md is 7.3 KB long, well organised into 33 sections with 6 code examples: a thorough specification that gives an agent plenty to work with.
With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 29 days ago, so hunt-information-disclosure is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
hunt-information-disclosure compared with similar skills
All 4 of these similar skills score higher than hunt-information-disclosure; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hunt-information-disclosure (this skill)by uphiago | 89 | 1.3k | 29d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 86.6k | 15d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| ai-job-searchby MadsLorentzen | 100 | 44.6k | 1d ago | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | today | CLAUDE.md |
Frequently asked questions
- How do I install hunt-information-disclosure?
- Run
npx skills add uphiago/recon-skills --skill hunt-information-disclosure. The install tabs above show the steps for each supported agent. - Which AI agents does hunt-information-disclosure work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is hunt-information-disclosure safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hunt-information-disclosure still maintained?
- The repository was last updated 29 days ago, so hunt-information-disclosure is actively maintained.
Skill content
View source on GitHubname: hunt-information-disclosure description: Hunt error leakage, DVCS exposure, source maps, config files, and differential oracles. category: redteam version: 1.1.0 revision_date: 2026-07-25 license: MIT platforms: [linux] compatibility: Requires curl, python3, httpx tags: [redteam, information-disclosure, error-leakage, source-maps, config, enumeration] related_skills:
- source-leak-hunt
- js-secrets-extraction
- error-log-mining
- web-enumeration
Information Disclosure Hunting
Hunt for information exposure through stack traces, debug endpoints, versioned path discovery, source maps, and differential oracles. Each disclosure amplifies other vulnerabilities — a version number enables CVE targeting, a server path enables LFI, a schema leak enables auth bypass, and an error message reveals internal infrastructure.
When to Use
- Applications return verbose error messages with stack traces, file paths, or SQL fragments.
- Source maps (.js.map) are deployed to production.
- Versioned static assets reveal framework/CMS versions.
- API responses differ by object existence (user enumeration by status/length/time).
- Debug endpoints, health checks, or status pages expose internal state.
Quick Detection
# Trigger errors on common paths
for path in "/nonexistent" "/%00" "/.." "/error" "/debug"; do
curl --max-time 30 --connect-timeout 10 -sk "https://target.com$path" | grep -iE "stack|trace|exception|error|warning|debug|line [0-9]+" | head -5
done
Procedure
Phase 1 — Error & Exception Leakage
# Trigger errors with malformed input
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/users?id='"
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://target.com/api/login" -d '{"username":null}'
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/search?q=%00"
# Check response for sensitive data
# Stack traces → file paths, line numbers, framework version
# SQL errors → table names, column names, DB type
# Deserialization errors → class names, serialization format
# Template errors → template paths, engine type
# Fuzz for debug endpoints
for path in "/debug" "/__debug__" "/debugbar" "/_debug_toolbar" "/.well-known/debug" \
"/actuator" "/actuator/info" "/actuator/env" "/actuator/health"; do
curl --max-time 30 --connect-timeout 10 -sk "https://target.com$path" -w "\n%{http_code} — $path\n" -o /dev/null
done
Phase 2 — DVCS & Config File Discovery
# Git, SVN, Mercurial exposure
for path in "/.git/HEAD" "/.git/config" "/.svn/entries" "/.hg/store/"; do
curl --max-time 30 --connect-timeout 10 -sk "https://target.com$path" -w "%{http_code} — $path\n" -o /dev/null
done
# Config and env files
for pattern in ".env" ".env.local" ".env.production" ".env.staging" \
"config.json" "config.yml" "settings.py" "settings.php" \
"wp-config.php" "web.config" "app.config"; do
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/$pattern" -w "%{http_code} — $pattern\n" -o /dev/null
done
# Backup files
for pattern in "backup.zip" "backup.sql" "dump.sql" "db.sql" \
"database.sql" "export.sql" "site.tar.gz" "backup.tar.gz"; do
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/$pattern" -w "%{http_code} — $pattern\n" -o /dev/null
done
Phase 3 — Source Map Exploitation
# Find .js.map files
curl --max-time 30 --connect-timeout 10 -sk "https://target.com" | grep -Eo '[^"\s]+\.js\.map' | sort -u
# Download and extract
wget "https://target.com/static/app.js.map"
node -e "
const m=require('./app.js.map');
m.sources.forEach((s,i)=>require('fs').writeFileSync(s.split('/').pop(),m.sourcesContent[i]));
console.log('Extracted '+m.sources.length+' files');
"
# Look for NEXT_PUBLIC env vars in extracted source
grep -r "NEXT_PUBLIC_" extracted_files/ | cut -d= -f1 | sort -u
Phase 4 — Differential Oracles
# User enumeration via status code
for id in {1..50}; do
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/users/$id" -w "$id — %{http_code}\n" -o /dev/null
done
# Object existence via response size
for id in {1..100}; do
size=$(curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/orders/$id" -w "%{size_download}" -o /dev/null)
echo "$id — $size bytes"
done | awk '$2 > 100 {print "EXISTS: "$0}'
# Timing oracle for blind enumeration
for id in {1..50}; do
time curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/users/$id" -o /dev/null -w "%{time_total}s $id\n"
done | sort -rn
# ETag/304 oracle
for id in {1..10}; do
etag=$(curl --max-time 30 --connect-timeout 10 -skI "https://target.com/api/users/$id" | grep -i etag)
echo "$id: $etag"
done
Phase 5 — Version & Technology Discovery
# Framework version from static assets
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/static/admin/css/base.css" | head -5
curl --max-time 30 --connect-timeout 10 -sk "https://target.com" | grep -Eo '(?:Django|Laravel|Rails|Express|Next\.js|Nuxt)[\s/]*v?[0-9.]+'
# Package manager lock files
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/composer.lock" | jq -r '.packages[] | select(.version) | "\(.name)@\(.version)"' 2>/dev/null
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/package-lock.json" | jq -r '.packages | to_entries[] | "\(.key)@\(.value.version)"' 2>/dev/null
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/yarn.lock" | head -30
Phase 6 — Chaining Disclosures
Each disclosure type provides inputs for other attack vectors:
| Disclosure | Chains to | |---|---| | Framework version | CVE database lookup | | Server path | LFI path traversal | | Internal IP | SSRF target | | API schema | Auth bypass via undocumented endpoint | | Dependency version | Supply chain vulnerability | | NEXT_PUBLIC variables | API key/Supabase/Firebase access | | SQL error | SQL injection confirmation + DB type |
Pitfalls
- Not every error message is exploitable. A generic "An error occurred" page with no details is not a finding.
- Source maps may be empty or stripped. Verify extracted content before reporting.
- Differential oracles are statistical. Confirm with at least 3 samples before reporting.
.gitexposure must contain actual repo data, not just HTTP 200 on a path. A catch-all SPA may return 200 for/.git/HEADwithout serving git data.- Version disclosure alone is usually LOW severity. Chain it — version → CVE → exploit.
Verification
- Error message contains actionable internal data (file path, SQL query, framework version).
- Source map extraction produces real source files with identifiable code (not just webpack bootstrap).
- Differential oracle consistently distinguishes between existing and non-existing resources.
- Chain the disclosure to another vulnerability before reporting — standalone info disclosure is rarely critical.
- For config files: the leaked data must contain credentials, API keys, or connection strings (not just generic config).
Related Skills
source-leak-hunt— Focused on.env,.git, and config file leakage.js-secrets-extraction— API keys and tokens in JavaScript bundles.error-log-mining— PHP error logs with credential and query leakage.web-enumeration— Path discovery that reveals sensitive endpoints.
Related Skills
Agent-Reach
86.6kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ai-job-search
44.6kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
