hunt-metrics-exposure
Hunt public /metrics, /health, and actuator endpoints leaking AI usage, DB pools, and operational intelligence.
Install / Use
npx skills add uphiago/recon-skills --skill hunt-metrics-exposureInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Tags
Our assessment of hunt-metrics-exposure
hunt-metrics-exposure scores 84/100 on our quality scale, 2297th of 4,259 Development & Engineering skills we index.
Its SKILL.md is 5.3 KB long, well organised into 19 sections with 3 code examples: a solid amount of guidance for an agent.
With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 29 days ago, so hunt-metrics-exposure is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
hunt-metrics-exposure compared with similar skills
All 4 of these similar skills score higher than hunt-metrics-exposure; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hunt-metrics-exposure (this skill)by uphiago | 84 | 1.3k | 29d ago | SKILL.md |
| ai-job-searchby MadsLorentzen | 100 | 44.6k | 1d ago | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | today | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 8d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 8d ago | SKILL.md |
Frequently asked questions
- How do I install hunt-metrics-exposure?
- Run
npx skills add uphiago/recon-skills --skill hunt-metrics-exposure. The install tabs above show the steps for each supported agent. - Which AI agents does hunt-metrics-exposure work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is hunt-metrics-exposure safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hunt-metrics-exposure still maintained?
- The repository was last updated 29 days ago, so hunt-metrics-exposure is actively maintained.
Skill content
View source on GitHubname: hunt-metrics-exposure description: "Hunt public /metrics, /health, and actuator endpoints leaking AI usage, DB pools, and operational intelligence." version: 1.1.0 revision_date: 2026-07-25 license: MIT category: redteam tags: [metrics, exposure, hunt, redteam]
When to Use
The target uses modern observability tooling (Go, .NET, Java, Node.js). These frameworks often expose /metrics, /health, and /status endpoints that are forgotten behind auth. Unlike application data leaks, metrics leaks reveal the ENTIRE operational profile: which AI models are used, how many users are active, database connection exhaustion, and third-party service dependencies.
Phase 1 — Discover Metrics Endpoints
TARGET="https://target.com"
# Common observability paths
for ep in metrics health status ready live readyz healthz \
actuator/health actuator/metrics actuator/prometheus \
Telescope telescope horizon debug; do
code=$(curl --max-time 30 --connect-timeout 10 -sk -o /tmp/metrics_${ep}.txt -w "%{http_code}" \
"${TARGET}/${ep}" 2>/dev/null)
if [ "$code" = "200" ]; then
size=$(wc -c < /tmp/metrics_${ep}.txt)
echo " /${ep}: HTTP 200 (${size} bytes)"
fi
done
Phase 2 — Analyze Prometheus Metrics
# Count unique metric families (each reveals a subsystem)
grep -c '^# HELP' /tmp/metrics_metrics.txt
# Extract AI/ML model usage
grep -i 'ai_\|model\|llm\|openai\|gemini\|copilot' /tmp/metrics_metrics.txt
# Extract database pool states
grep -i 'db_pool\|database\|connection' /tmp/metrics_metrics.txt
# Extract third-party dependencies
grep -i 'stripe\|openai\|sendgrid\|twilio\|email' /tmp/metrics_metrics.txt
# Extract request volumes (user activity)
grep -i 'http_request\|api_request\|grpc_request' /tmp/metrics_metrics.txt
# Extract circuit breaker states (service health)
grep -i 'circuit_breaker' /tmp/metrics_metrics.txt
Phase 3 — Analyze Health/Status Endpoints
# Spring Boot Actuator
curl --max-time 30 --connect-timeout 10 -sk "${TARGET}/actuator/health" | python3 -m json.tool
curl --max-time 30 --connect-timeout 10 -sk "${TARGET}/actuator/metrics" | python3 -m json.tool
curl --max-time 30 --connect-timeout 10 -sk "${TARGET}/actuator/env" | python3 -m json.tool # May leak env vars
# Custom health endpoints
curl --max-time 30 --connect-timeout 10 -sk "${TARGET}/health" | python3 -m json.tool
curl --max-time 30 --connect-timeout 10 -sk "${TARGET}/api/health" | python3 -m json.tool
# Laravel Telescope (if exposed)
curl --max-time 30 --connect-timeout 10 -sk "${TARGET}/telescope/requests" | head -c 500
What Metrics Reveal
| Metric | Intelligence Gained |
|--------|-------------------|
| ai_analyzer_output_total{model="gpt-5-mini"} | Which AI models are used, usage volume |
| db_pool_idle_connections{pool="api"} | Database pool sizing, connection exhaustion risk |
| circuit_breaker_state{client="stripe"} | Third-party dependencies and their health |
| clinical_copilot_sse_active | Real-time user count for specific features |
| http_requests_total | Request volume, peak hours, user activity |
| app_version / build_info | Deployed version, build timestamps |
Verification
- Confirmed exposure:
/metricsreturns Prometheus text format (lines starting with# HELPor# TYPE) - Actuator exposure:
/actuator/healthreturns JSON with component statuses - False positive: Endpoint returns
{"status":"ok"}only (minimal health check, not a metrics leak) - Severity upgrade: If
/actuator/envor/actuator/configpropsis exposed → CRITICAL (environment variables leaked)
What Next
- AI model usage metrics → pivot to
hunt-llm-ai(prompt injection on discovered models) - DB pool metrics showing overload → DoS attack surface identified
- Circuit breaker states for Stripe/email → infrastructure dependency map for chained attacks
- Combine with
hunt-schema-enumerationfor full target profile
Verification
Run this self-test to confirm metrics-exposure hunting readiness:
-
Skill integrity — confirm the skill file is readable and well-formed:
grep -q "name: hunt-metrics-exposure" SKILL.md && echo "PASS: skill frontmatter present" || echo "FAIL" grep -q "revision_date:" SKILL.md && echo "PASS: revision date present" || echo "FAIL" -
Category check — confirm the skill has a category:
grep -q "category:" SKILL.md && echo "PASS: category present" || echo "FAIL" -
Pitfalls section — confirm pitfalls are documented:
grep -q "^## Pitfalls" SKILL.md && echo "PASS: pitfalls section present" || echo "FAIL"
All 3 tests verify the skill is properly structured and ready for use.
Pitfalls
- Prometheus /metrics without secrets — metrics endpoints exposing request counts are informational. Need labels containing PII, internal hostnames, or credentials.
- Spring Boot Actuator /actuator/metrics — metrics are intentionally exposed for monitoring. Only report if they leak sensitive data (usernames in labels, internal IPs).
- JMX without auth — JMX exposure without authentication is critical only if write operations (MBean invocation) are possible. Read-only JMX is informational.
- Health endpoint without sensitive data —
/health,/status,/readyendpoints are designed to be public. Need leaked internal data.
Related Skills
ai-job-search
44.6kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
