Agent skill

Hunt Clickjacking

by elementalsouls in elementalsouls/Claude-BugHunter

Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisible iframe and trick victims into clicking buttons they cannot see (UI redressing).

MITAuto-check passedBackend & APIs

Install Hunt Clickjacking

skills CLI
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-clickjacking -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elementalsouls/Claude-BugHunter hunt-clickjacking --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-clickjacking .claude/skills/hunt-clickjacking && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-clickjacking
GitHub stars
4.8k
Token cost
~1.1k tokens
SKILL.md length
410 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisible iframe and trick victims into clicking buttons they cannot see (UI redressing).

  • Tasks that involve Authentication
  • SKILL.md covers What is Clickjacking, Protection Headers, How to Test and False Positives, plus 1 more section
  • Calls curl
  • Tasks that involve OAuth and OpenID Connect

What it does

Hunt Clickjacking is an agent skill from elementalsouls/Claude-BugHunter. Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisible iframe and trick victims into clicking buttons they cannot see (UI redressing). Targets: login flows, money transfers, account settings, OAuth confirmation pages. Confirm by fetching the page, then PROVE it frames in a real browser and a sensitive state-changing action survives the cross-site context (SameSite cookies / framebusting JS can defeat it) — header-absence alone is not a finding.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication and OAuth and OpenID Connect. The repository describes itself as: A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes… The licence is MIT.

When your agent uses it

  • Tasks that involve Authentication
  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “/hunt-clickjacking”

What it can do on your machine

Read from SKILL.md and the folder at commit a04bb83. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt Clickjacking loads about 1.1k tokens when it runs. Until then it costs about 133 tokens; SKILL.md has 410 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~133
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elementalsouls/Claude-BugHunter at commit a04bb83, republished under its MIT licence (© elementalsouls). 410 words, ~1,050 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-clickjacking/SKILL.md (or your agent's skills folder).
name
hunt-clickjacking
description
Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisible iframe and trick victims into clicking buttons they cannot see (UI redressing). Targets: login flows, money transfers, account settings, OAuth confirmation pages. Confirm by fetching the page, then PROVE it frames in a real browser and a sensitive state-changing action survives the cross-site context (SameSite cookies / framebusting JS can defeat it) — header-absence alone is not a finding.
sources
hackerone_public, public_research
report_count
6

What is Clickjacking

Clickjacking (UI Redressing) lets an attacker load a target page inside a transparent iframe on a malicious site. The victim sees the attacker's decoy UI but clicks the hidden target UI beneath it. No JavaScript on the target is required.

Highest-value targets:

  • Login / authentication pages — force login with attacker credentials
  • Money transfer / checkout / "confirm payment" buttons
  • Account settings (email change, password change, 2FA disable)
  • OAuth / social-login "Authorize app" confirmation dialogs
  • Admin actions (delete, promote user, change role)

Protection Headers

Two mechanisms prevent framing:

X-Frame-Options: DENY              # strongest — blocks all framing
X-Frame-Options: SAMEORIGIN        # allows same-origin frames only
Content-Security-Policy: frame-ancestors 'none'     # CSP equivalent of DENY
Content-Security-Policy: frame-ancestors 'self'     # CSP equivalent of SAMEORIGIN

If NEITHER is present, the page is frameable from any origin.

How to Test

Header-absence is the trigger for investigation, not the finding. Two steps:

Step 1 — Header check (screening). Fetch the target page and inspect the response headers:

curl -sI https://target.example/account/transfer | grep -iE 'x-frame-options|content-security-policy'

If BOTH X-Frame-Options and CSP frame-ancestors are absent, the page is a candidate. If either is present and restrictive (DENY/SAMEORIGIN/frame-ancestors 'none'|'self'), stop — it's protected.

Step 2 — Prove it actually frames and clicks (required for a real finding). Build a minimal PoC and load it in a real browser:

html
<!doctype html>
<h1>Win a prize — click below</h1>
<iframe src="https://target.example/account/transfer"
        style="opacity:0.1;position:absolute;top:0;left:0;width:1000px;height:800px"></iframe>

Confirm ALL of the following, or it is not exploitable:

  • The page actually renders inside the iframe (no framebusting JS that blanks/redirects it — e.g. if(top!==self) breakout, or a Sec-Fetch-Dest/JS frame check).
  • The sensitive action still works while framed — critically, the action must succeed cross-site. If it relies on a session cookie set SameSite=Lax or SameSite=Strict (the modern default), the cookie is not sent on the cross-site framed request, and the clickjack fails. Verify the victim's authenticated state carries into the frame.
  • The target is a state-changing action (transfer, settings/email/password change, 2FA disable, OAuth authorize, admin action), not a read-only page.

Strategy: target the most sensitive action pages first — severity scales directly with what the victim is tricked into doing.

Show full SKILL.md (118 more words)Show less

False Positives

  • Public, read-only pages (home/marketing) lacking frame protection are low/informational — no sensitive action to redress.
  • APIs and non-HTML endpoints (JSON, images) are not clickjacking targets.
  • Header-absence alone is NOT a finding. SameSite cookies, framebusting JS, or the lack of any sensitive framed action can each fully defeat it — which is why Step 2 is mandatory.

Proof Requirements

A valid clickjacking report shows: (1) the target page rendered inside an attacker-controlled iframe in a real browser, (2) a sensitive state-changing action reachable by a framed click while the victim is authenticated (cookies survive the cross-site context), and (3) a screenshot/recording of the overlay. Reporting missing headers with no working frame PoC is a documentation-quality issue, not a vulnerability.

© elementalsouls, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt-clickjacking of elementalsouls/Claude-BugHunter.

Open the folder on GitHubat commit a04bb83

Compare with similar skills

Hunt Clickjacking next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Clickjacking compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Clickjacking this skillelementalsouls/Claude-BugHunter4.8k—~1.1kAutomated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
OAuth Account Setupspinabot/brigade11k—~878Automated safety check: PassMIT
Auth Implementation Patternsynulihao/AgentSkillOS61710 repos~4.4kAutomated safety check: PassNone

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • OAuth Account Setup

    spinabot/brigade

    Connects an OAuth 2.0 account such as Gmail with the built-in oauth_authorize tool: an authorization link, automatic code capture and sealed token storage.

    11k GitHub stars~878 tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    617 GitHub starsUsed in 10 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Socialite Development

    hexlet-volunteers/hexlet-sicp

    Manages OAuth social authentication with Laravel Socialite. An agent skill from hexlet-volunteers/hexlet-sicp.

    114 GitHub starsUsed in 5 repos~1.2k tokens
    Backend & APIsAuto-check passed

More from elementalsouls/Claude-BugHunter

All 17 skills in this repo
  • Hunt API Misconfig

    elementalsouls/Claude-BugHunter

    Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.

    4.8k GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Hunt Ato

    elementalsouls/Claude-BugHunter

    Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains.

    4.8k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Hunt Fintech Graphql

    elementalsouls/Claude-BugHunter

    Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding…

    4.8k GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed
  • Hunt HTTP Smuggling

    elementalsouls/Claude-BugHunter

    Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Hunt JWT Crypto

    elementalsouls/Claude-BugHunter

    Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g.

    4.8k GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • Hunt RAG Vector

    elementalsouls/Claude-BugHunter

    Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) — persistent corpus poisoning that survives across sessions and users (distinct from…

    4.8k GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Hunt Clickjacking

What does Hunt Clickjacking do?

Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisible iframe and trick victims into clicking buttons they cannot see (UI redressing). Hunt Clickjacking is an agent skill from elementalsouls/Claude-BugHunter. Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisible iframe and trick victims into clicking buttons they cannot see (UI redressing).

When should I use Hunt Clickjacking?

Hunt Clickjacking fits situations like: tasks that involve Authentication; tasks that involve OAuth and OpenID Connect.

How do I install Hunt Clickjacking in Claude Code?

Run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-clickjacking -a claude-code`. Or copy the skill folder (skills/hunt-clickjacking in elementalsouls/Claude-BugHunter) into .claude/skills/hunt-clickjacking in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Clickjacking in Codex?

Run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-clickjacking -a codex`. Or copy the skill folder (skills/hunt-clickjacking in elementalsouls/Claude-BugHunter) into .agents/skills/hunt-clickjacking in your project. Codex loads it when a task matches its description.

Can I use Hunt Clickjacking in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-clickjacking -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-clickjacking, .gemini/skills/hunt-clickjacking, .github/skills/hunt-clickjacking and .opencode/skills/hunt-clickjacking in your project.

What does Hunt Clickjacking need to run?

Going by SKILL.md and its folder, Hunt Clickjacking needs the command-line tools its instructions call (curl).

Does Hunt Clickjacking access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Hunt Clickjacking safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Clickjacking use?

Hunt Clickjacking is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Clickjacking use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Clickjacking?

Skills that share tags, products or a category with Hunt Clickjacking: Fortify Development (coollabsio/coolify, 63k stars), Security Review (doorkeeper-gem/doorkeeper, 5.5k stars), Cognito (itsmostafa/aws-agent-skills, 1.2k stars) and OAuth Account Setup (spinabot/brigade, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Clickjacking?

elementalsouls (a GitHub user) maintains it in elementalsouls/Claude-BugHunter, which has 4,791 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.

Source: elementalsouls/Claude-BugHunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.