agentsclimarketplace

Hunt new program

Skill 3dcom2711/thrunt-god/thrunt-god/examples/brute-force-to-persistence/.github/skills/hunt-new-program

Run threat hunting workflows for agentic IDEs like Claude Code, OpenCode, and Gemini in one command

Install
npx -y skills add 3dcom2711/thrunt-god --skill hunt-new-program

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Initialize a threat hunting program with an environment map, tool inventory, huntmap, and empty execution directories

SKILL.md

3.4 KB, 738 tokens by cl100k_base, as published. Nobody here has run it

<context> **Flags:** - `--auto` - Use the provided brief as the primary source of truth and ask only for missing critical facts. </context> <objective> Initialize a threat hunting program.

These hunt-native artifacts are the source of truth for the program.

Creates:

  • .planning/config.json
  • .planning/MISSION.md
  • .planning/HYPOTHESES.md
  • .planning/SUCCESS_CRITERIA.md
  • .planning/HUNTMAP.md
  • .planning/STATE.md
  • .planning/environment/ENVIRONMENT.md
  • .planning/QUERIES/
  • .planning/RECEIPTS/

Bootstrap should only scaffold the program. Do not seed sample queries, sample receipts, or completed phases. Unknown environment facts, tools, retention windows, and owners must remain TBD unless the operator confirms them. Confirmed bootstrap facts such as the program name, mode, opened date, and initial phase/status must be filled immediately.

After this command: Run /hunt-map-environment to capture confirmed facts, or edit .planning/environment/ENVIRONMENT.md manually and continue later. </objective>

<execution_context> @.github/thrunt-god/workflows/hunt-bootstrap.md @.github/thrunt-god/templates/config.json @.github/thrunt-god/templates/mission.md @.github/thrunt-god/templates/hypotheses.md @.github/thrunt-god/templates/success-criteria.md @.github/thrunt-god/templates/hunt-program-huntmap.md @.github/thrunt-god/templates/hunt-state.md @.github/thrunt-god/templates/environment-map.md </execution_context>

<process> Execute the bootstrap workflow from @.github/thrunt-god/workflows/hunt-bootstrap.md in program mode. Drive the conversation through `.planning/environment/ENVIRONMENT.md` and the operator toolchain before defining later hunt phases. Create `.planning/QUERIES/` and `.planning/RECEIPTS/` as empty directories only. Do not load query-log or receipt templates during bootstrap; those belong to `/hunt-run` after real execution begins. Default behavior is scaffold-first: write confirmed facts only and leave unknown values as `TBD` instead of inventing sample content. Create `.planning/config.json` during bootstrap if it does not already exist so runtime, settings, and connector commands are immediately usable. Never hand-write `.planning/config.json`; use `thrunt-tools config-new-program` and `thrunt-tools config-set` so the file stays valid THRUNT config. Use built-in connector ids exactly as the runtime registers them, for example `splunk` and `elastic`; do not substitute `elasticsearch`. When writing connector profiles, use `base_url` for the runtime URL field; do not invent or substitute `endpoint`. Only configure connector profiles when auth type and secret ref names are confirmed. Never invent placeholder env vars or placeholder secrets for blocked connectors. When writing `secret_refs`, each confirmed secret must use the THRUNT object shape `{ "type": "env", "value": "ENV_VAR_NAME" }` rather than a raw string. Keep connector narrative, status notes, and access commentary in `ENVIRONMENT.md`, not in ad hoc config keys. Do not leave bootstrap-known fields as `TBD` after writing the files. Write the hunt artifacts directly. Preserve any existing user-authored content unless the user explicitly wants a reset. </process>

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.