Agent skill

Hunt API

by Encod3d-Sec in Encod3d-Sec/TORCH

API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse.

MITAuto-check passedBackend & APIs

Install Hunt API

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill hunt-api -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH hunt-api --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt/hunt-api .claude/skills/hunt-api && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-api
GitHub stars
329
Token cost
~1.9k tokens
SKILL.md length
919 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse.

  • Works in 9 steps: Enumerate. Parse Swagger/OpenAPI for… → BOLA / IDOR (API #1). Swap object IDs… → Broken function-level auth (BFLA). Call… → …
  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers Wiki, Attack surface signals, Methodology and Confirmation gate, plus 2 more sections
  • Calls python3

What it does

Hunt API is an agent skill from Encod3d-Sec/TORCH. API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse. OWASP API Top 10. Wiki-first, FIND schema output.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Web application vulnerabilities, gRPC and Protobuf and GraphQL. It works with gRPC, GraphQL and OpenAPI. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Tasks that involve Web application vulnerabilities
  • Tasks that involve gRPC and Protobuf
  • Tasks that involve GraphQL

Example prompts

  • “/hunt-api”

Requirements

  • Python 3

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Enumerate. Parse Swagger/OpenAPI for every endpoint + param; GraphQL introspection (__schema); gRPC server reflection (grpcurl -plaintext…
  2. BOLA / IDOR (API #1). Swap object IDs across accounts (numeric, UUID, in body/path/header) - the dominant API bug. Swapping IDs to pull…
  3. Broken function-level auth (BFLA). Call admin/privileged methods as a low-priv user; swap the HTTP verb (GET -> PUT/DELETE); hit the…
  4. Mass assignment. Add fields the client never sends (role, isAdmin, verified, balance) to JSON bodies; look for the privilege/state change…
  5. Excessive data exposure. The API returns more than the UI shows (full objects, other users' fields, internal flags) - inspect the raw…
  6. Auth. JWT flaws ([[jwt-attacks]]: alg:none, weak secret, kid injection), API-key reuse, missing auth on some routes, OAuth scope creep.
  7. GraphQL specifics. Introspection, batching/aliases (rate-limit/brute bypass), nested-query DoS, field suggestion leaks. Payloads…
  8. gRPC specifics. Reflection to enumerate; grpcurl to call methods; tamper protobuf fields; run the same authz tests as REST.
  9. Rate limit / resource. Unbounded pagination, no throttle on sensitive actions (OTP/login). Prove the throttle is absent with a bounded…

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt API loads about 1.9k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 919 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 919 words, ~1,914 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-api/SKILL.md (or your agent's skills folder).
name
hunt-api
description
API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse. OWASP API Top 10. Wiki-first, FIND schema output.

Hunt: API Security

Assumes hunt-core for the scope gate, two-account rule, confirmation gate, enumeration limits, stop conditions, wiki protocol, FIND output, and Deadends. Do not re-derive any of that here.

Wiki

qmd_query "API REST GraphQL gRPC BOLA BFLA mass assignment excessive data exposure OWASP API Top 10" via wiki-search MCP

Hub: [[web-moc]] (live web index). Primary page: [[api-security]]. Payload arsenal: wiki/payloads/api.md. Anchors: [[api-testing]], [[graphql-attacks]]. Variants: [[grpc-web-attacks]] (gRPC-Web / protobuf transcoder abuse), [[rsql-injection]] with the [[rsql]] payload (RSQL/FIQL filter-query injection, e.g. Spring Data REST), [[rate-limit-bypass]] (header/race/distributed-source throttle bypass), [[redos]] payload (catastrophic-backtracking regex DoS in an input validator), [[jwt-attacks]] (token flaws).

For object-level authorization (BOLA/IDOR) see hunt-idor.

Attack surface signals

/api/, /v1/, /graphql, /rest/, gRPC (application/grpc, HTTP/2), Swagger UI (/swagger, /api-docs, /openapi.json), mobile/SPA backends.

Rank before testing. Not all surface is equally likely to be broken:

  • Undocumented endpoints present in the spec (Swagger/introspection) but never called by the UI - the classic BFLA surface; nobody tested the route the client does not exercise.
  • GraphQL introspection and the mutations/fields it reveals that the client never invokes.
  • Batching and alias endpoints - one request, many operations; per-item authorization and rate limiting are frequently applied to the request, not each operation.
  • Bulk and export endpoints - one call, many objects; much higher severity per finding.
  • Non-GET verbs on read-looking routes - GET /orders/123 authorized, PATCH/DELETE not.
  • Newest features - authorization middleware lags new code; a route written outside the conventions misses it.

Methodology

Setup: two accounts per hunt-core (A owns, B attacks, separate profiles). Get the spec if any - Swagger/OpenAPI, GraphQL introspection, .proto.

Drive it through Burp for operator visibility. Push the load-bearing requests (the BOLA cross-account swap, the mass-assignment body, the BFLA verb/route call) into Repeater via Skill(hunt-burp) / the native Burp MCP (mcp__burp__*) so the operator can replay and inspect them; brute/fuzz belongs in Intruder (send_to_intruder), not a hand-rolled loop. A quick throwaway curl per account for the writeup PoC is fine.

  1. Enumerate. Parse Swagger/OpenAPI for every endpoint + param; GraphQL introspection (__schema); gRPC server reflection (grpcurl -plaintext <h> list, then list <svc> / describe). No spec? Discover endpoints with ffuf -w <api-wordlist> -u https://HOST/FUZZ and fingerprint hosts with httpx, not a hand curl loop. This is service / endpoint DISCOVERY, not object enumeration - it is bounded by the engagement RoE (no_dos, scan-rate caps), NOT by the 5-to-20 object cap. Do not clamp the wordlist to 20.
  2. BOLA / IDOR (API #1). Swap object IDs across accounts (numeric, UUID, in body/path/header) - the dominant API bug. Swapping IDs to pull other accounts' records IS object enumeration: bounded to 5 identifiers by default, 20 ceiling with operator approval, 0 under no_bruteforce, per hunt-core. Two or three adjacent IDs prove the sequential pattern; cite a total/pagination count for scale, never a sweep. Full bounded-sample loop and the trusted-identifier test live in hunt-idor. -> overlaps hunt-idor.
  3. Broken function-level auth (BFLA). Call admin/privileged methods as a low-priv user; swap the HTTP verb (GET -> PUT/DELETE); hit the undocumented endpoints from the spec.
  4. Mass assignment. Add fields the client never sends (role, isAdmin, verified, balance) to JSON bodies; look for the privilege/state change to actually take effect (confirm from a fresh read, step below).
  5. Excessive data exposure. The API returns more than the UI shows (full objects, other users' fields, internal flags) - inspect the raw response, not the rendered page.
  6. Auth. JWT flaws ([[jwt-attacks]]: alg:none, weak secret, kid injection), API-key reuse, missing auth on some routes, OAuth scope creep.
  7. GraphQL specifics. Introspection, batching/aliases (rate-limit/brute bypass), nested-query DoS, field suggestion leaks. Payloads: [[graphql-attacks]].
  8. gRPC specifics. Reflection to enumerate; grpcurl to call methods; tamper protobuf fields; run the same authz tests as REST.
  9. Rate limit / resource. Unbounded pagination, no throttle on sensitive actions (OTP/login). Prove the throttle is absent with a bounded burst; honor no_bruteforce/no_dos - do not actually brute credentials or OTPs and never run this at volume against a live auth endpoint. See [[rate-limit-bypass]].
Show full SKILL.md (298 more words)Show less

When a direct call 403s or the extra field is stripped, it is not closed. Parameter pollution (?id=A&id=B - check and fetch may read different occurrences), array/nested wrapping of the field ({"user":{"role":"admin"}}), casing and separator variants of a mass-assign key (isAdmin/is_admin/admin), alternate content-type (form vs JSON vs XML), verb-override headers (X-HTTP-Method-Override), version downgrade (/v1/ predates the middleware /v2/ has - the most reliable), and batching to skip per-item authorization.

Chain: mass assignment -> privilege escalation. A role:admin/isAdmin:true that actually takes effect turns the whole BFLA admin surface reachable - re-run step 3 as the escalated principal. For the broader workflow/state-tampering angle hand off to hunt-bizlogic.

Distill a confirmed, GENERIC pattern (product + endpoint + impact, no client host): python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page techniques/web/api-security.md

Confirmation gate

NOT confirmation: a 200 echoing your own request back; an empty or shell response; B seeing an object that is shared, public, or org-visible; a body you have not compared against A's baseline; a BFLA endpoint returning 200 without the privileged action actually performed; a mass-assignment write returning 200 with the extra field accepted but the privileged field never verified in effect; any result not re-verified in a clean session.

IS confirmation:

  • BOLA - B's low-priv session returns A's actual data, matching A's own baseline response, with A's legitimate/shared access ruled out, reproduced in a clean session.
  • BFLA - a low-priv token reaching AND executing an admin/privileged function (perform the action, do not just get a 200).
  • Mass assignment - the privileged field (role/isAdmin/balance) verified in effect from a fresh authenticated read, not merely accepted in the request body.

Severity

  • CRITICAL - unauthenticated admin action, or cross-tenant data access.
  • HIGH - BOLA/BFLA reaching other users' data or functions; mass-assignment privilege escalation.
  • MEDIUM - excessive data exposure; missing or weak rate limiting.

Deadends

Append: - [ ] API on <host> <endpoint> -- BOLA/BFLA/mass-assign all enforced;
              extra fields ignored; JWT validated; introspection off

Record what you tried (pollution/array/verb/version-downgrade/batch), not just that it failed.

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt/hunt-api of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Hunt API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt API compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt API this skillEncod3d-Sec/TORCH329—~1.9kAutomated safety check: PassMIT
API Auditbriiirussell/cybersecurity-skills412—~2.8kAutomated safety check: NotesMIT
API Architectcuriositech/some_claude_skills2431 repos~1.4kAutomated safety check: PassMIT
API ForgeEliasOulkadi/shokunin114—~2.9kAutomated safety check: PassMIT
API Security ReviewOWASP/secure-agent-playbook186—~744Automated safety check: PassCC-BY-4.0
SpikardGoldziher/spikard123—~799Automated safety check: PassMIT

Similar skills

  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    412 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • API Architect

    curiositech/some_claude_skills

    Expert API designer for REST, GraphQL, gRPC architectures. An agent skill from curiositech/some_claude_skills.

    243 GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check passed
  • API Forge

    EliasOulkadi/shokunin

    Design REST/GraphQL APIs with OpenAPI 3.1, error handling, pagination, rate limiting, webhooks, and idempotency.

    114 GitHub stars~2.9k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • API Security Review

    OWASP/secure-agent-playbook

    Comprehensive API security review against OWASP API Security Top 10 (2023).

    186 GitHub stars~744 tokensUpdated 11 days ago
    Backend & APIsAuto-check passed
  • Spikard

    Goldziher/spikard

    Scaffold Spikard projects and generate code from OpenAPI, AsyncAPI, OpenRPC, GraphQL, and Protobuf schemas using the Spikard CLI or its MCP server.

    123 GitHub stars~799 tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Dotnet API

    novotnyllc/dotnet-artisan

    Builds ASP.NET Core APIs, EF Core data access, gRPC, SignalR, and backend services with middleware, security (OAuth, JWT, OWASP), resilience, messaging, OpenAPI, .NET Aspire, Semantic Kernel…

    233 GitHub stars~1.6k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Hunt Idor

    Encod3d-Sec/TORCH

    IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…

    329 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Hunt API

What does Hunt API do?

API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse. Hunt API is an agent skill from Encod3d-Sec/TORCH. API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse.

When should I use Hunt API?

Hunt API fits situations like: tasks that involve Web application vulnerabilities; tasks that involve gRPC and Protobuf; tasks that involve GraphQL.

How do I install Hunt API in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-api -a claude-code`. Or copy the skill folder (skills/hunt/hunt-api in Encod3d-Sec/TORCH) into .claude/skills/hunt-api in your project. Claude Code loads it when a task matches its description.

How do I install Hunt API in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-api -a codex`. Or copy the skill folder (skills/hunt/hunt-api in Encod3d-Sec/TORCH) into .agents/skills/hunt-api in your project. Codex loads it when a task matches its description.

Can I use Hunt API in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill hunt-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-api, .gemini/skills/hunt-api, .github/skills/hunt-api and .opencode/skills/hunt-api in your project.

What does Hunt API need to run?

Going by SKILL.md and its folder, Hunt API needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Hunt API access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hunt API safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt API use?

Hunt API is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt API use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt API?

Skills that share tags, products or a category with Hunt API: API Audit (briiirussell/cybersecurity-skills, 412 stars), API Architect (curiositech/some_claude_skills, 243 stars), API Forge (EliasOulkadi/shokunin, 114 stars) and API Security Review (OWASP/secure-agent-playbook, 186 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt API?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.