Skip to content
appsgit

Hunt LLM AI

Hunt LLM AI is an agent skill (a SKILL.md file) from elementalsouls/Claude-BugHunter. Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). It works with Claude Code, Codex and OpenCode and has 4,784 GitHub stars across a repository of 4 listed skills.

github.com/elementalsouls/Claude-BugHunter/skills/hunt-llm-ai (opens in a new tab)

  • Multi-skill repo
  • Plugin marketplace
  • Security
  • Actively maintained

Add this skill

Claude

This repository is a Claude Code plugin marketplace. In Claude Code:

/plugin marketplace add elementalsouls/Claude-BugHunter
/plugin install claude-bughunter@elementalsouls

In the Claude apps, zip the hunt-llm-ai folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

ChatGPT / Codex

Codex reads skills from .agents/skills/ in a repo or ~/.agents/skills/ for every project:

git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git
cp -r Claude-BugHunter/skills/hunt-llm-ai .agents/skills/hunt-llm-ai   # repo; ~/.agents/skills for all projects

Standalone skills also load in the ChatGPT desktop app.

Cursor

Cursor loads skills from .cursor/skills/ (or ~/.cursor/skills/) and also reads .claude/skills/:

git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git
cp -r Claude-BugHunter/skills/hunt-llm-ai .cursor/skills/hunt-llm-ai   # project; ~/.cursor/skills for all projects

Source (checked Oct 7, 2026): code.claude.com/docs/en/skills (opens in a new tab), code.claude.com/docs/en/plugin-marketplaces (opens in a new tab), support.claude.com/en/articles/12512180-using-skills-in-claude (opens in a new tab), learn.chatgpt.com/docs/build-skills (opens in a new tab), cursor.com/docs/context/skills (opens in a new tab)

What this skill does

Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). Patterns: direct injection ('ignore previous instructions'), indirect injection via documents/web pages/email the model reads, ASCII smuggling (Unicode Tags block U+E0000-U+E007F, invisible to humans, decoded by the model), tool-use exfiltration (model has fetch/browse tool, attacker injects OOB URL, model exfils chat…

When it triggers

  • Use when hunting AI features, chatbots, RAG, agentic systems, MCP.

More skills in elementalsouls/Claude-BugHunter

4 skills are listed from this repository.

FAQ

Hunt LLM AI FAQ

Still curious? Email info@appsgit.com.

What is the Hunt LLM AI skill?

Hunt LLM AI is an agent skill (a SKILL.md file) from elementalsouls/Claude-BugHunter. Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). It works with Claude Code, Codex and OpenCode and has 4,784 GitHub stars across a repository of 4 listed skills. Its SKILL.md lives at github.com/elementalsouls/Claude-BugHunter/skills/hunt-llm-ai.

How do I install the Hunt LLM AI skill?

In Claude Code, run /plugin marketplace add elementalsouls/Claude-BugHunter and then /plugin install claude-bughunter@elementalsouls. For Codex or Cursor, copy the hunt-llm-ai folder into .agents/skills/ or .cursor/skills/.

Is the Hunt LLM AI skill free?

Yes. The repository is open source under the MIT license.

Is Hunt LLM AI maintained?

The repository's most recent commit was on Oct 6, 2026. Its latest release is v2.1. appsgit only lists skills from repositories with a commit in the last six months.