Best for
- Use when recon finds VCS paths, 403 on hidden dirs, or backup/config leaks during authorized testing.
ok-helloworld/vibe-pentest/references/pentest_skills/insecure-source-code-management/SKILL.md
Source control and artifact exposure (.git, .svn, .hg, backups, .env). Use when recon finds VCS paths, 403 on hidden dirs, or backup/config leaks during authorized testing.
Decision brief
AI LOAD INSTRUCTION: This skill covers detection of exposed version-control metadata, common backup artifacts, and related misconfigurations. Use only in authorized assessments. Treat recovered credentials and URLs as sensitive; do not exfiltrate real data beyond scope. For broa…
Compatibility matrix
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/ok-helloworld/vibe-pentest --skill "references/pentest_skills/insecure-source-code-management"Inspect the Agent Skill "insecure-source-code-management" from https://github.com/ok-helloworld/vibe-pentest/blob/04d3a99ae3a595dcce1468faa74b66209acf20f8/references/pentest_skills/insecure-source-code-management/SKILL.md at commit 04d3a99ae3a595dcce1468faa74b66209acf20f8. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
High-value paths to probe first (GET or HEAD, respect rate limits):
A 403 on the directory plus 200 on HEAD strongly indicates exposure.
/.git/HEAD — valid repo often returns plain text like:
A 403 on the directory plus 200 on HEAD strongly indicates exposure.
Review the “Key files to prioritize” section in the pinned source before continuing.
Permission review
No configured static risk pattern was detected
This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.
Evidence record
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 89/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 238 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
AI LOAD INSTRUCTION: This skill covers detection of exposed version-control metadata, common backup artifacts, and related misconfigurations. Use only in authorized assessments. Treat recovered credentials and URLs as sensitive; do not exfiltrate real data beyond scope. For broad discovery workflow, cross-load recon-for-sec and recon-and-methodology when those skills exist in the workspace.
High-value paths to probe first (GET or HEAD, respect rate limits):
/.git/HEAD
/.git/config
/.svn/entries
/.svn/wc.db
/.hg/requires
/.bzr/README
/.DS_Store
/.env
Routing note: quickly probe these paths first; for full recon workflow, load methodology from recon-for-sec and recon-and-methodology before deeper testing.
/.git/HEAD — valid repo often returns plain text like:ref: refs/heads/main
/.git/config — may expose remote.origin.url, user identity, or embedded credentials./.git/index, /.git/objects/ — partial object store access enables reconstruction with the right tools.404 — path likely absent or fully blocked at the edge.403 on /.git/ — directory may exist but listing is denied; still try direct file URLs:/.git/HEAD
/.git/config
/.git/logs/HEAD
/.git/refs/heads/main
A 403 on the directory plus 200 on HEAD strongly indicates exposure.
| Path | Why it matters |
|---|---|
.git/config | Remotes, credentials, hooks paths |
.git/logs/HEAD | Commit history, reflog-style leakage |
.git/refs/heads/* | Branch tips, commit SHAs |
.git/packed-refs | Packed branch/tag refs |
.git/objects/** | Object blobs for reconstruction |
/.svn/entries — XML or text metadata listing paths and revisions./.svn/wc.db — SQLite working copy database (PRAGMA table_info after download).Example probe:
GET /.svn/entries HTTP/1.1
GET /.svn/wc.db HTTP/1.1
/.hg/requires — small text file listing repository features; confirms Mercurial metadata.GET /.hg/requires HTTP/1.1
GET /.hg/store/ HTTP/1.1
/.bzr/README and /.bzr/branch-format for Bazaar metadata..DS_Store/.DS_Store can encode directory and filename listings.gehaxelt/ds-store, lijiejie/ds_store_exp — parse .DS_Store offline.Probe (adjust for app root and naming conventions):
/.env
/backup.zip
/backup.tar.gz
/wwwroot.rar
/backup.sql
/config.php.bak
/.config.php.swp
location /.git { deny all; } — may return 403 for /.git/ while still allowing or denying specific subpaths depending on rules./.git/HEAD → ref: refs/heads/ pattern? → run git-dumper / GitTools / GitHacker; review config and logs/HEAD for secrets./.hg/requires → success? → mercurial dumper./.bzr/README → Bazaar tooling or manual path walk./.DS_Store, /.env, common backup extensions on app root and parent paths.Note: coordinate with recon skills—set scope and request rate first, then run targeted VCS/backup validation.
Alternatives
coreyhaines31/marketingskills
When the user wants to plan, design, or implement an A/B test or experiment, or build a growth experimentation program. Also use when the user mentions "A/B test," "split test," "experiment," "test this change," "variant copy," "multivariate test," "hypothesis," "should I test this," "which version is better," "test two versions," "statistical significance," "how long should I run this test," "growth experiments," "experiment velocity," "experiment backlog," "ICE score," "experimentation program
alirezarezvani/claude-skills
App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist
dotnet/skills
Migrates .NET test projects from VSTest to Microsoft.Testing.Platform (MTP). Use when user asks to "migrate to MTP", "switch from VSTest", "enable Microsoft.Testing.Platform", "use MTP runner", set OutputType=Exe only for test projects in Directory.Build.props, or mentions EnableMSTestRunner, EnableNUnitRunner, or UseMicrosoftTestingPlatformRunner. USE FOR: MTP behavioral differences vs VSTest (exit code 8, zero tests discovered, --ignore-exit-code, TESTINGPLATFORM_EXITCODE_IGNORE); centralizing
JasonColapietro/suede-creator-skills
Suede-owned experimentation discipline for hypotheses, sample sizing, test duration, significance, and repeatable experiment programs. Use when comparing variants, deciding whether a result is reliable, or building an experiment backlog and cadence. NOT FOR: analytics instrumentation (use suede-analytics), post-click conversion diagnosis (use suede-site-alchemy), or writing the variant copy itself (use suede-copy).