agentsclimarketplace

Hunt plan

Skill 3dcom2711/thrunt-god/thrunt-god/examples/brute-force-to-persistence/.github/skills/hunt-plan

Run threat hunting workflows for agentic IDEs like Claude Code, OpenCode, and Gemini in one command

Install
npx -y skills add 3dcom2711/thrunt-god --skill hunt-plan

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Create phase plans for a threat hunt with exact telemetry tasks, receipts, and query outputs

SKILL.md

0.9 KB, 191 tokens by cl100k_base, as published. Nobody here has run it

<objective> Plan a hunt phase from the current HUNTMAP.

HUNTMAP.md remains the source of truth for phase layout and sequencing.

Creates or updates:

  • .planning/phases/[phase-slug]/
  • CONTEXT.md
  • PLAN.md files
  • .planning/STATE.md
  • .planning/HUNTMAP.md when phase metadata changes

After this command: Run /hunt-run <phase>. </objective>

<execution_context> @.github/thrunt-god/workflows/hunt-plan.md @.github/thrunt-god/templates/context.md @.github/thrunt-god/templates/phase-prompt.md </execution_context>

<process> Execute the hunt planning workflow from @.github/thrunt-god/workflows/hunt-plan.md. Plans must name the telemetry source, intended evidence, and required receipts. </process>

Gives 0 of the 12 instructions most plan spec skills give in 191 tokens

Counted across 1,100 of the 1,860 authors here whose files we hold, read 2026-08-06

  • ask one question at a timein 46 of 1100, across 38 files
  • Break plans into vertical slicesin 28 of 1100, across 10 files
  • Publish issues in dependency orderin 27 of 1100, across 9 files
  • Iterate until user approves the breakdownin 24 of 1100, across 6 files
  • Explore the repository to understand the codebase statein 24 of 1100, across 7 files
  • Use domain glossary vocabularyin 23 of 1100, across 5 files
  • Apply correct triage labels to published issuesin 23 of 1100, across 5 files
  • Write failing tests before implementation codein 23 of 1100, across 18 files
  • Prefer AFK slices over HITLin 22 of 1100, across 7 files
  • ask clarifying questions until requirements are concretein 21 of 1100, across 13 files
  • Respect existing architecture decision recordsin 20 of 1100, across 5 files
  • write a specification before writing any codein 20 of 1100, across 12 files

Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.