hunt-information-disclosure

Installation
SKILL.md

Information Disclosure Hunting

Hunt for information exposure through stack traces, debug endpoints, versioned path discovery, source maps, and differential oracles. Each disclosure amplifies other vulnerabilities — a version number enables CVE targeting, a server path enables LFI, a schema leak enables auth bypass, and an error message reveals internal infrastructure.

When to Use

  • Applications return verbose error messages with stack traces, file paths, or SQL fragments.
  • Source maps (.js.map) are deployed to production.
  • Versioned static assets reveal framework/CMS versions.
  • API responses differ by object existence (user enumeration by status/length/time).
  • Debug endpoints, health checks, or status pages expose internal state.

Quick Detection

Installs
11
GitHub Stars
1.2K
First Seen
Jul 9, 2026
hunt-information-disclosure — uphiago/recon-skills