deep-hunt

Perform manual security testing on business workflows to identify high-impact vulnerabilities.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill deep-hunt
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: deep-hunt
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/meta/deep-hunt
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill deep-hunt

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill addresses the limitation of shallow automated scanners by providing a structured, manual-first methodology for hunting high-impact vulnerabilities in complex business logic.

Core Features & Use Cases

  • Workflow-Specific Playbooks: Provides targeted testing steps for critical business areas like billing, authentication, and GraphQL.
  • Boundary-Based Testing: Enforces a rigorous six-boundary testing framework (Actor, Object, State, Shape, Time, Side-effect) to ensure comprehensive coverage.
  • Use Case: When performing a pentest on a web application, use this skill to systematically audit the recovery and invite workflows for IDORs, race conditions, and authorization bypasses.

Quick Start

Invoke the deep-hunt skill by providing the specific business workflow you wish to audit such as deep-hunt billing.

Frequently Asked Questions about deep-hunt

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find high-impact vulnerabilities in complex business logic during a pentest?

To find high-impact vulnerabilities in business logic, you need a deep-dive manual security testing methodology that systematically audits specific workflows like billing or authentication for logic-based flaws rather than relying solely on automated scanners.

What is the best way to test for IDORs and race conditions in web application workflows?

Testing for IDORs and race conditions in web applications requires applying a boundary-based testing framework across actor, object, state, shape, time, and side-effect dimensions to generate report-ready evidence for authorized bug bounty engagements.

Can I use this manual security testing approach for GraphQL and authentication audits?

Yes, you can use this manual security testing approach for GraphQL and authentication audits by applying targeted workflow-specific playbooks that execute systematic boundary testing across critical business areas to identify authorization bypasses.

Does bug bounty hunting require systematic boundary testing across actor and state dimensions?

Bug bounty hunting requires systematic boundary testing across actor, state, and side-effect dimensions to ensure comprehensive coverage and uncover complex authorization bypasses that shallow automated scanners typically miss during reconnaissance.

Why does automated scanning fail to find high-impact vulnerabilities in business logic?

Automated scanning fails to find high-impact vulnerabilities in business logic because it lacks the structured, manual-first methodology needed to understand and test specific workflow boundaries, resulting in shallow coverage of complex attack surfaces.

When should I not use automated scanners for penetration testing?

You should not rely solely on automated scanners for penetration testing when auditing critical business workflows like recovery and invite processes, as they miss logic-based attack surface analysis and fail to produce report-ready evidence for high-impact flaws.