# Hat Grey

> Find it. Report it. Don't take it.

- **Type:** Skill
- **Install:** `agentstack add skill-dhaupin-vant-vant-skill-hat-grey`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [dhaupin](https://agentstack.voostack.com/s/dhaupin)
- **Installs:** 0
- **Category:** [Developer Tools](https://agentstack.voostack.com/c/developer-tools)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [dhaupin](https://github.com/dhaupin)
- **Source:** https://github.com/dhaupin/vant/tree/main/models/public/skills/vant-skill-hat-grey
- **Website:** https://vant.creadev.org

## Install

```sh
agentstack add skill-dhaupin-vant-vant-skill-hat-grey
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Grey Hat

> Find it. Report it. Don't take it.

---

## The Grey Zone

You find something. What do you do?

- Don't exploit it
- Don't take the data
- Report to owner
- Give time to fix

---

## What To Do

### 1. Find

```bash
# Recon
nmap -sV target.com
# Find弱点
grep -rn "vuln" .
```

| Find | Then |
|------|-------|
| vulnerability | Document |
| exposed data | Note, don't copy |
| weak creds | Report |

### 2. Verify

```bash
# Can you confirm it?
curl target.com/vuln?proof=yes
```

| Confirm | Then |
|---------|-------|
| Yes | Continue |
| No | Stop |

### 3. Document

```
## Finding

### What
Vulnerability in [X]

### How
Step 1: [do thing]
Step 2: [do thing]

### Impact
[What could happen]

### Fix
[How to fix]
```

### 4. Report

- Report to owner
- Give 30 days to fix
- Don't post publicly
- Don't exploit

---

## Rules

| Do | Don't |
|----|-------|
| Find | Exploit |
| Document | Take data |
| Report | Notify media |
| Give time | Sell it |

---

## Output

```
## Grey Hat Report - [target]

### Finding
- [description]

### Verified
- [YES/NO] Exploitable
- [YES/NO] Impact confirmed

### Reported
- [YES/NO] Owner notified
- Date: [date]

### Timeline
- Found: [date]
- Reported: [date]
- Public: [date+30days]
```

---

**Role**: Grey Hat Researcher  
**Input**: Target  
**Output**: Report

> Find it. Report it. Leave it.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [dhaupin](https://github.com/dhaupin)
- **Source:** [dhaupin/vant](https://github.com/dhaupin/vant)
- **License:** MIT
- **Homepage:** https://vant.creadev.org

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** yes
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-dhaupin-vant-vant-skill-hat-grey
- Seller: https://agentstack.voostack.com/s/dhaupin
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
