Search
Backend & APIs · By elementalsouls
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering. | elementalsouls/ | 4.8k | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 2 | 2.Hunt Ato Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains. | elementalsouls/ | 4.8k | — | ~3.4k | Automated safety check: Pass | MIT | today |
| 3 | Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding… | elementalsouls/ | 4.8k | — | ~3.5k | Automated safety check: Pass | MIT | today |
| 4 | Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g. | elementalsouls/ | 4.8k | — | ~2.3k | Automated safety check: Pass | MIT | today |
| 5 | Discover a single-page-app's hidden backend API from its public JS bundle, then test that API for broken access control / missing authentication. | elementalsouls/ | 4.8k | — | ~2.2k | Automated safety check: Notes | MIT | today |
| 6 | Hunting skill for auth bypass vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~8.2k | Automated safety check: Pass | MIT | today |
| 7 | Hunting skill for sqli vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~5.5k | Automated safety check: Pass | MIT | today |
| 8 | Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisible iframe and trick victims into clicking buttons they cannot see (UI redressing). | elementalsouls/ | 4.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 9 | Hunt CAPTCHA Bypass — 6 distinct patterns: (1) CAPTCHA field simply omitted from the request (server-side validation absent), (2) CAPTCHA token replayed from a solved challenge (no single-use… | elementalsouls/ | 4.8k | — | ~1.5k | Automated safety check: Pass | MIT | today |
| 10 | Hunt Forgot Password / Account Recovery Authentication Flaws — 5 distinct patterns: (1) username enumeration via different responses for valid vs invalid email, (2) reset token exposed directly in… | elementalsouls/ | 4.8k | — | ~1.4k | Automated safety check: Pass | MIT | today |