Agent skill

Hunt Forgot Password

by elementalsouls in elementalsouls/Claude-BugHunter

Hunt Forgot Password / Account Recovery Authentication Flaws — 5 distinct patterns: (1) username enumeration via different responses for valid vs invalid email, (2) reset token exposed directly in…

MITAuto-check passedBackend & APIs

Install Hunt Forgot Password

skills CLI
$ npx skills add elementalsouls/Claude-BugHunter --skill hunt-forgot-password -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elementalsouls/Claude-BugHunter hunt-forgot-password --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-forgot-password .claude/skills/hunt-forgot-password && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-forgot-password
GitHub stars
4.8k
Token cost
~1.4k tokens
SKILL.md length
660 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Hunt Forgot Password / Account Recovery Authentication Flaws — 5 distinct patterns: (1) username enumeration via different responses for valid vs invalid email, (2) reset token exposed directly in…

  • Works in 5 steps: Username Enumeration via Password Reset → Weak / Predictable Reset Tokens → Token Not Bound to Session or IP → …
  • Tasks that involve Rate limiting
  • SKILL.md covers Autonomous Testing Priority, Vulnerability Classes in This… and Related Skills
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Hunt Forgot Password is an agent skill from elementalsouls/Claude-BugHunter. Hunt Forgot Password / Account Recovery Authentication Flaws — 5 distinct patterns: (1) username enumeration via different responses for valid vs invalid email, (2) reset token exposed directly in the API response body, (3) reset token not invalidated after use (replay), (4) password reset link works from a different IP/browser (no binding), (5) no rate limit on the reset request endpoint. These are the standalone recovery-flow broken-auth primitives — distinct from reset-email host-header poisoning…

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Rate limiting. The repository describes itself as: A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes… The licence is MIT.

When your agent uses it

  • Tasks that involve Rate limiting

Example prompts

  • “/hunt-forgot-password”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Username Enumeration via Password Reset
  2. Weak / Predictable Reset Tokens
  3. Token Not Bound to Session or IP
  4. Reset Link Doesn't Expire
  5. No Rate Limit on Reset Endpoint

What it can do on your machine

Read from SKILL.md and the folder at commit 210aad1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • hackerone.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt Forgot Password loads about 1.4k tokens when it runs. Until then it costs about 233 tokens; SKILL.md has 660 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~233
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elementalsouls/Claude-BugHunter at commit 210aad1, republished under its MIT licence (© elementalsouls). 660 words, ~1,439 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-forgot-password/SKILL.md (or your agent's skills folder).
name
hunt-forgot-password
description
Hunt Forgot Password / Account Recovery Authentication Flaws — 5 distinct patterns: (1) username enumeration via different responses for valid vs invalid email, (2) reset token exposed directly in the API response body, (3) reset token not invalidated after use (replay), (4) password reset link works from a different IP/browser (no binding), (5) no rate limit on the reset request endpoint. These are the standalone recovery-flow broken-auth primitives — distinct from reset-email host-header poisoning (hunt-host-header) and the full ATO chain (hunt-ato owns password-reset as an ATO path; prove the primitive here, chain it there). Detection: trace the full forgot-password flow from request to token to use; check response diffs between valid/invalid emails; test token replay after consumption. Medium to High (enumeration=Medium, token-reuse=High, account-takeover=Critical when chained to known-email).
sources
hackerone_public, public_research
report_count
6

Autonomous Testing Priority

Start with username enumeration — it's the fastest win and gates the rest.

Pattern 1 — Username enumeration (response difference for valid vs invalid email):

  1. POST to the forgot-password endpoint with a clearly invalid email (e.g. nonexistent@fakedomain12345.com) — record the response body, status code, and length
  2. POST with an email you know exists (or try common patterns like admin@target.com, test@target.com, user@target.com)
  3. Compare responses: different message ("Email sent" vs "Email not found"), different HTTP status, or meaningfully different body length = username enumeration confirmed
  4. Proof: enumeration is confirmed when the two responses differ measurably (baseline vs probe) in message text, status code, or body length

Pattern 2 — Reset token exposed in the API response: Some APIs return the reset token directly in the response body (instead of only emailing it). POST to the forgot-password endpoint and look for a token, link, or code in the JSON/HTML response. If a token appears that lets you reset the password, that's an immediate account-takeover vector.

Pattern 3 — Reset token replay (reuse after use):

  1. Complete a full password reset cycle: request token → use it to reset password
  2. Immediately try submitting the same token again to the reset-password endpoint
  3. If the second submission returns 200 or "success" → token not invalidated after use

Pattern 4 — No rate limit on reset requests: Submit the forgot-password endpoint 10-20 times rapidly with the same email. If all succeed without a 429, lockout, or CAPTCHA → no rate limit (enumeration + token flooding is possible).

Content-type: Forgot-password endpoints are often JSON-based REST APIs. Use application/x-www-form-urlencoded only if the endpoint is a traditional HTML form (check the login page's HTML to determine form encoding).

Proof: Username enumeration = measurably different response (body/status/length). Token exposure = token in response body. Token replay = second successful use of a consumed token.


Vulnerability Classes in This Skill

1. Username Enumeration via Password Reset

Different error messages for valid vs invalid accounts leaks the user list without authentication. Even timing differences (fast "no user found" vs slow "email queued") count.

High-value targets: admin accounts, employee email patterns, API keys derived from usernames.

2. Weak / Predictable Reset Tokens

A reset token derived from timestamp, username, or sequential IDs can be brute-forced:

  • base64(email + timestamp) — decodable
  • 4-6 digit numeric code — 10K guesses, easily feasible with no rate limit
  • Sequential token=1234, token=1235 — trivially enumerable
Show full SKILL.md (275 more words)Show less
3. Token Not Bound to Session or IP

Most apps generate a token, email it, and accept it from any browser. A truly bound token should only work from the same IP or require the original session cookie. If neither is enforced → link forwarding = account takeover.

Token leak via Referer / third-party resources. When the token rides in the reset-page URL (/reset?token=…) and that page loads any cross-origin resource (analytics, ads, fonts, a CDN image), the full URL — token included — leaks to that third party in the Referer header. Check the reset page's outbound requests: if the token appears in any cross-origin Referer, it's harvestable without the victim's inbox. Same leak via a <meta name=referrer> misconfig or an outbound link the victim clicks from the reset page. Disclosed token-leak→ATO class: https://hackerone.com/reports/173551.

Common best practice: reset tokens expire within ~15–60 minutes (no hard RFC mandates the exact value; OWASP recommends a short, single-use lifetime). If a token from 24 hours ago still works → persistence risk for phishing attacks.

5. No Rate Limit on Reset Endpoint

An uncapped reset endpoint enables:

  • Email flooding (DoS against victim's inbox)
  • Token brute-force if the token space is small
  • Username enumeration at scale

  • hunt-ato — owns the account-takeover CHAIN (password-reset is its path #1). This skill finds/proves the recovery-flow primitive; hand off to hunt-ato to assemble the full takeover.
  • hunt-cache-poison — host-header injection during reset email generation (different vulnerability, same flow)
  • hunt-brute-force — rate-limit testing pattern applies to the reset endpoint too
  • hunt-auth-bypass — if the reset flow can be skipped entirely (go to /reset-password?token= with empty/null token)
  • hunt-mfa-bypass — if MFA is required after reset, test the bypass there

© elementalsouls, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt-forgot-password of elementalsouls/Claude-BugHunter.

Open the folder on GitHubat commit 210aad1

Compare with similar skills

Hunt Forgot Password next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Forgot Password compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Forgot Password this skillelementalsouls/Claude-BugHunter4.8k—~1.4kAutomated safety check: PassMIT
Add Hosted Keysimstudioai/sim30k—~3.4kAutomated safety check: PassApache-2.0
Upstash Ratelimit TSupstash/ratelimit-js2k—~313Automated safety check: PassMIT
Repo2skillzhangyanxs/repo2skill246—~3.6kAutomated safety check: PassNone
Better Auth Security Best PracticesEpicenterHQ/epicenter4.8k—~896Automated safety check: PassCustom licence
Dload Fetch Toolphp-internal/dload105—~1.1kAutomated safety check: PassBSD-3-Clause

Similar skills

  • Add Hosted Key

    simstudioai/sim

    Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.

    30k GitHub stars~3.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Upstash Ratelimit TS

    upstash/ratelimit-js

    Official

    Lightweight guidance for using the Redis Rate Limit TypeScript SDK, including setup steps, basic usage, and pointers to advanced algorithm, features, pricing, and traffic‑protection docs.

    2k GitHub stars~313 tokensUpdated 14 days ago
    Backend & APIsAuto-check passed
  • Repo2skill

    zhangyanxs/repo2skill

    Convert GitHub/GitLab/Gitee repositories into comprehensive OpenCode Skills using embedded LLM calls with multiple mirrors and rate limit handling

    246 GitHub stars~3.6k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Dload Fetch Tool

    php-internal/dload

    Get a CLI tool — native binary or PHAR — from a GitHub release into a project folder with dload (vendor/bin/dload).

    105 GitHub stars~1.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • API Gateway

    itsmostafa/aws-agent-skills

    AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub stars~2.2k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed

More from elementalsouls/Claude-BugHunter

All 19 skills in this repo
  • Hunt Business Logic

    elementalsouls/Claude-BugHunter

    Hunting skill for business logic vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Hunt API Misconfig

    elementalsouls/Claude-BugHunter

    Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.

    4.8k GitHub stars~4.5k tokensUpdated today
    Auto-check passed
  • Hunt Ato

    elementalsouls/Claude-BugHunter

    Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains.

    4.8k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Hunt Fintech Graphql

    elementalsouls/Claude-BugHunter

    Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding…

    4.8k GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Hunt HTTP Smuggling

    elementalsouls/Claude-BugHunter

    Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Hunt JWT Crypto

    elementalsouls/Claude-BugHunter

    Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g.

    4.8k GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Categories

Questions about Hunt Forgot Password

What does Hunt Forgot Password do?

Hunt Forgot Password / Account Recovery Authentication Flaws — 5 distinct patterns: (1) username enumeration via different responses for valid vs invalid email, (2) reset token exposed directly in…. Hunt Forgot Password is an agent skill from elementalsouls/Claude-BugHunter. Hunt Forgot Password / Account Recovery Authentication Flaws — 5 distinct patterns: (1) username enumeration via different responses for valid vs invalid email, (2) reset token exposed directly in the API response body, (3) reset token not invalidated after use (replay), (4) password reset link works from a different IP/browser (no binding), (5) no rate limit on the reset request endpoint.

When should I use Hunt Forgot Password?

Hunt Forgot Password fits situations like: tasks that involve Rate limiting.

How do I install Hunt Forgot Password in Claude Code?

Run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-forgot-password -a claude-code`. Or copy the skill folder (skills/hunt-forgot-password in elementalsouls/Claude-BugHunter) into .claude/skills/hunt-forgot-password in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Forgot Password in Codex?

Run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-forgot-password -a codex`. Or copy the skill folder (skills/hunt-forgot-password in elementalsouls/Claude-BugHunter) into .agents/skills/hunt-forgot-password in your project. Codex loads it when a task matches its description.

Can I use Hunt Forgot Password in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elementalsouls/Claude-BugHunter --skill hunt-forgot-password -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-forgot-password, .gemini/skills/hunt-forgot-password, .github/skills/hunt-forgot-password and .opencode/skills/hunt-forgot-password in your project.

What does Hunt Forgot Password need to run?

SKILL.md names no scripts, command-line tools or credentials: Hunt Forgot Password is instructions for the agent only.

Does Hunt Forgot Password access the network?

SKILL.md names 1 domain. As links in the text: hackerone.com. This is read from the text; nothing was executed.

Is Hunt Forgot Password safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Forgot Password use?

Hunt Forgot Password is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Forgot Password use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Forgot Password?

Skills that share tags, products or a category with Hunt Forgot Password: Add Hosted Key (simstudioai/sim, 30k stars), Upstash Ratelimit TS (upstash/ratelimit-js, 2k stars), Repo2skill (zhangyanxs/repo2skill, 246 stars) and Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Forgot Password?

elementalsouls (a GitHub user) maintains it in elementalsouls/Claude-BugHunter, which has 4,846 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 9, 2026.

Source: elementalsouls/Claude-BugHunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.