SkillAgentSearch skills...

hunt-metrics-exposure

Hunt public /metrics, /health, and actuator endpoints leaking AI usage, DB pools, and operational intelligence.

Install / Use

npx skills add uphiago/recon-skills --skill hunt-metrics-exposure

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

84/100

Supported Platforms

Universal

Tags

Our assessment of hunt-metrics-exposure

hunt-metrics-exposure scores 84/100 on our quality scale, 2297th of 4,259 Development & Engineering skills we index.

Its SKILL.md is 5.3 KB long, well organised into 19 sections with 3 code examples: a solid amount of guidance for an agent.

With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
26/30
Structure
18/20
Description
12/15
Adoption
13/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 29 days ago, so hunt-metrics-exposure is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

hunt-metrics-exposure compared with similar skills

All 4 of these similar skills score higher than hunt-metrics-exposure; compare them before choosing.

SkillScoreStarsUpdatedFormat
hunt-metrics-exposure (this skill)by uphiago841.3k29d agoSKILL.md
ai-job-searchby MadsLorentzen10044.6k1d agoCLAUDE.md
claude-howtoby luongnv8910041.7ktodayCLAUDE.md
algorithmic-artby anthropics100177.9k8d agoSKILL.md
pptxby anthropics100177.9k8d agoSKILL.md

Frequently asked questions

How do I install hunt-metrics-exposure?
Run npx skills add uphiago/recon-skills --skill hunt-metrics-exposure. The install tabs above show the steps for each supported agent.
Which AI agents does hunt-metrics-exposure work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is hunt-metrics-exposure safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is hunt-metrics-exposure still maintained?
The repository was last updated 29 days ago, so hunt-metrics-exposure is actively maintained.

name: hunt-metrics-exposure description: "Hunt public /metrics, /health, and actuator endpoints leaking AI usage, DB pools, and operational intelligence." version: 1.1.0 revision_date: 2026-07-25 license: MIT category: redteam tags: [metrics, exposure, hunt, redteam]

When to Use

The target uses modern observability tooling (Go, .NET, Java, Node.js). These frameworks often expose /metrics, /health, and /status endpoints that are forgotten behind auth. Unlike application data leaks, metrics leaks reveal the ENTIRE operational profile: which AI models are used, how many users are active, database connection exhaustion, and third-party service dependencies.


Phase 1 — Discover Metrics Endpoints

TARGET="https://target.com"

# Common observability paths
for ep in metrics health status ready live readyz healthz \
  actuator/health actuator/metrics actuator/prometheus \
  Telescope telescope horizon debug; do
  code=$(curl --max-time 30 --connect-timeout 10 -sk -o /tmp/metrics_${ep}.txt -w "%{http_code}" \
    "${TARGET}/${ep}" 2>/dev/null)
  if [ "$code" = "200" ]; then
    size=$(wc -c < /tmp/metrics_${ep}.txt)
    echo "  /${ep}: HTTP 200 (${size} bytes)"
  fi
done

Phase 2 — Analyze Prometheus Metrics

# Count unique metric families (each reveals a subsystem)
grep -c '^# HELP' /tmp/metrics_metrics.txt

# Extract AI/ML model usage
grep -i 'ai_\|model\|llm\|openai\|gemini\|copilot' /tmp/metrics_metrics.txt

# Extract database pool states
grep -i 'db_pool\|database\|connection' /tmp/metrics_metrics.txt

# Extract third-party dependencies
grep -i 'stripe\|openai\|sendgrid\|twilio\|email' /tmp/metrics_metrics.txt

# Extract request volumes (user activity)
grep -i 'http_request\|api_request\|grpc_request' /tmp/metrics_metrics.txt

# Extract circuit breaker states (service health)
grep -i 'circuit_breaker' /tmp/metrics_metrics.txt

Phase 3 — Analyze Health/Status Endpoints

# Spring Boot Actuator
curl --max-time 30 --connect-timeout 10 -sk "${TARGET}/actuator/health" | python3 -m json.tool
curl --max-time 30 --connect-timeout 10 -sk "${TARGET}/actuator/metrics" | python3 -m json.tool
curl --max-time 30 --connect-timeout 10 -sk "${TARGET}/actuator/env" | python3 -m json.tool  # May leak env vars

# Custom health endpoints
curl --max-time 30 --connect-timeout 10 -sk "${TARGET}/health" | python3 -m json.tool
curl --max-time 30 --connect-timeout 10 -sk "${TARGET}/api/health" | python3 -m json.tool

# Laravel Telescope (if exposed)
curl --max-time 30 --connect-timeout 10 -sk "${TARGET}/telescope/requests" | head -c 500

What Metrics Reveal

| Metric | Intelligence Gained | |--------|-------------------| | ai_analyzer_output_total{model="gpt-5-mini"} | Which AI models are used, usage volume | | db_pool_idle_connections{pool="api"} | Database pool sizing, connection exhaustion risk | | circuit_breaker_state{client="stripe"} | Third-party dependencies and their health | | clinical_copilot_sse_active | Real-time user count for specific features | | http_requests_total | Request volume, peak hours, user activity | | app_version / build_info | Deployed version, build timestamps |


Verification

  • Confirmed exposure: /metrics returns Prometheus text format (lines starting with # HELP or # TYPE)
  • Actuator exposure: /actuator/health returns JSON with component statuses
  • False positive: Endpoint returns {"status":"ok"} only (minimal health check, not a metrics leak)
  • Severity upgrade: If /actuator/env or /actuator/configprops is exposed → CRITICAL (environment variables leaked)

What Next

  • AI model usage metrics → pivot to hunt-llm-ai (prompt injection on discovered models)
  • DB pool metrics showing overload → DoS attack surface identified
  • Circuit breaker states for Stripe/email → infrastructure dependency map for chained attacks
  • Combine with hunt-schema-enumeration for full target profile

Verification

Run this self-test to confirm metrics-exposure hunting readiness:

  1. Skill integrity — confirm the skill file is readable and well-formed:

    grep -q "name: hunt-metrics-exposure" SKILL.md && echo "PASS: skill frontmatter present" || echo "FAIL"
    grep -q "revision_date:" SKILL.md && echo "PASS: revision date present" || echo "FAIL"
    
  2. Category check — confirm the skill has a category:

    grep -q "category:" SKILL.md && echo "PASS: category present" || echo "FAIL"
    
  3. Pitfalls section — confirm pitfalls are documented:

    grep -q "^## Pitfalls" SKILL.md && echo "PASS: pitfalls section present" || echo "FAIL"
    

All 3 tests verify the skill is properly structured and ready for use.


Pitfalls

  • Prometheus /metrics without secrets — metrics endpoints exposing request counts are informational. Need labels containing PII, internal hostnames, or credentials.
  • Spring Boot Actuator /actuator/metrics — metrics are intentionally exposed for monitoring. Only report if they leak sensitive data (usernames in labels, internal IPs).
  • JMX without auth — JMX exposure without authentication is critical only if write operations (MBean invocation) are possible. Read-only JMX is informational.
  • Health endpoint without sensitive data — /health, /status, /ready endpoints are designed to be public. Need leaked internal data.

Related Skills

View on GitHub
GitHub Stars1.3k
CategoryDevelopment
Updated29d ago
Forks215

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions