hunt-grpc
elementalsouls/Claude-BugHunterHunt gRPC vulnerabilities — server reflection enabled (enumerate all services/methods), missing authentication / metadata-stripping on internal endpoints,…
Scores out of 100 · grade A
2026-08-17Works
40% of the score100/100
- Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score100/100
- no commits in the last 12 weeks
Adopted
20% of the score49/100
- 3,628 stars on the source repo.
Documented
15% of the score81/100
- 2,266 words with worked examples.
Install
npx skills add elementalsouls/Claude-BugHunter/hunt-grpcWhat it says it does
Hunt gRPC vulnerabilities — server reflection enabled (enumerate all services/methods), missing authentication / metadata-stripping on internal endpoints, plaintext gRPC over HTTP/2, internal endpoint disclosure, proto file leakage, gRPC-Web/grpc-gateway transcoding injection, and HTTP/2 Rapid Reset DoS (CVE-2023-44487). Use when target exposes port 50051 / 443 / 8443 / 9090 with HTTP/2, when grpcurl/grpcui detects reflection, when an Envoy or grpc-gateway proxy is fronting a microservice, or when recon reveals a microservice architecture.
Also in elementalsouls/Claude-BugHunter
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| apk-redteam-pipelineelementalsouls/Claude-BugHunter | clean | Skill | 3.6k stars | today | |
| bb-methodologyelementalsouls/Claude-BugHunter | clean | Skill | 3.6k stars | today | |
| bugcrowd-reportingelementalsouls/Claude-BugHunter | clean | Skill | 3.6k stars | today | |
| cloud-iam-deepelementalsouls/Claude-BugHunter | clean | Skill | 3.6k stars | today | |
| enterprise-vpn-attackelementalsouls/Claude-BugHunter | clean | Skill | 3.6k stars | today | |
| evidence-hygieneelementalsouls/Claude-BugHunter | clean | Skill | 3.6k stars | today |
Other backend & apis skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| find-skillsvercel-labs/skills | clean | Backend & APIs | 3,040,203 installs | 2 days ago | |
| write-api-referencevercel/next.js | clean | Backend & APIs | 142k stars | today | |
| fastapifastapi/fastapi | clean | Backend & APIs | 7,944 installs | yesterday | |
| paperclippaperclipai/paperclip | clean | Backend & APIs | 3,209 installs | today | |
| onchain-pay-open-apiccxt/ccxt | clean | Backend & APIs | 44k stars | today | |
| namecheapgithub/awesome-copilot | clean | Backend & APIs | 38k stars | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=elementalsouls%2FClaude-BugHunter)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
