Agent skill

Hunt Cache

by Encod3d-Sec in Encod3d-Sec/TORCH

Web cache poisoning + cache deception hunting - unkeyed input poisoning, cache-key analysis, path-confusion deception, header/parameter cloaking.

MITAuto-check passedSecurity

Install Hunt Cache

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill hunt-cache -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH hunt-cache --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt/hunt-cache .claude/skills/hunt-cache && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-cache
GitHub stars
329
Token cost
~1.6k tokens
SKILL.md length
782 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Web cache poisoning + cache deception hunting - unkeyed input poisoning, cache-key analysis, path-confusion deception, header/parameter cloaking.

  • Works in 5 steps: Identify the cache + cache key. Compare… → Cache poisoning (unkeyed input ->… → Cache deception (trick the cache into… → …
  • Security work in your project
  • SKILL.md covers Wiki, Attack surface, Methodology and Chaining, plus 5 more sections
  • Calls python3

What it does

Hunt Cache is an agent skill from Encod3d-Sec/TORCH. Web cache poisoning + cache deception hunting - unkeyed input poisoning, cache-key analysis, path-confusion deception, header/parameter cloaking. Wiki-first, FIND schema output.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Security work in your project

Example prompts

  • “/hunt-cache”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Identify the cache + cache key. Compare X-Cache/Age across requests; determine what is keyed (usually method + host + path + some query)…
  2. Cache poisoning (unkeyed input -> harmful response, then cached for others).
  3. Cache deception (trick the cache into storing a victim's private page).
  4. Confirm impact crosses a trust boundary - served to other users / discloses private data, not just your own session.
  5. Distill when confirmed (reusable unkeyed-header or deception-path trick, GENERIC, no client host): python3 scripts/wiki-stage.py --kind…

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt Cache loads about 1.6k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 782 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 782 words, ~1,611 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-cache/SKILL.md (or your agent's skills folder).
name
hunt-cache
description
Web cache poisoning + cache deception hunting - unkeyed input poisoning, cache-key analysis, path-confusion deception, header/parameter cloaking. Wiki-first, FIND schema output.

Hunt: Web Cache Attacks

Assumes hunt-core for the scope gate, two-account rule, confirmation gate, enumeration limits, stop conditions, wiki protocol, FIND output, and Deadends. Do not re-derive any of that here.

Wiki

qmd_query "web cache poisoning deception unkeyed input cache-key path confusion" via wiki-search MCP

Hub: [[web-moc]] (live web index). Primary page: [[web-cache-poisoning]]. Payload arsenal: wiki/payloads/web-cache.md. Anchors: [[web-cache-deception]], [[web-cache-attacks]]. Related: [[http-host-header-attacks]], [[http-request-smuggling]].

Attack surface

Needs a cache in front (CDN / Varnish / Cloudflare / Akamai / Fastly, or an app-layer cache). Signals: Age, X-Cache: hit/miss, Cache-Control, CF-Cache-Status headers; static-ish responses; responses that reflect a header or param.

Rank before testing:

  • Unkeyed headers that reflect - X-Forwarded-Host, X-Forwarded-Scheme, X-Host, X-Forwarded-For, plus custom headers a page reflects into links/scripts. Highest hit-rate poisoning vector; discover unkeyed inputs with Param Miner.
  • Path / parameter cloaking - static-looking suffixes and delimiter tricks (/account/profile.css, /account/profile/nonexistent.js, path-parameter ;, encoded %2f, fat GET) that desync what the cache keys on from what the origin serves. Primary deception vector.
  • CDN edges and normalization gaps - cache-key normalization (case, trailing slash, duplicate params) differing from origin routing; multi-CDN or origin-vs-edge disagreement.

Methodology

Drive load-bearing requests through Burp Repeater for operator visibility; use Param Miner to enumerate unkeyed headers/params. curl is fine for the quick keyed-vs-unkeyed loop.

  1. Identify the cache + cache key. Compare X-Cache/Age across requests; determine what is keyed (usually method + host + path + some query) vs unkeyed (most headers, some params). Always attach a unique cache-buster while probing so you never touch a shared key.
  2. Cache poisoning (unkeyed input -> harmful response, then cached for others).
    • Find an unkeyed input that affects the response (reflected header/param): X-Forwarded-Host, X-Forwarded-Scheme, X-Host, X-Forwarded-For, custom headers (Param Miner to discover).
    • Make it produce harm (XSS / redirect / resource swap), then confirm the cached poisoned response is served to a fresh request (cache-buster off) - and cross-session (see confirmation gate).
    • Fat GET, parameter cloaking, and cache-key normalization gaps as variants.
  3. Cache deception (trick the cache into storing a victim's private page).
    • Request a private page with an appended static-looking suffix/path: /account/profile.css, /account/profile/nonexistent.js, path-parameter ;, encoded %2f.
    • If the origin returns the private content but the cache stores it as static -> retrieve another user's data unauthenticated.
  4. Confirm impact crosses a trust boundary - served to other users / discloses private data, not just your own session.
  5. Distill when confirmed (reusable unkeyed-header or deception-path trick, GENERIC, no client host): python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page techniques/web/web-cache-poisoning.md (deception-path findings: --target-page techniques/web/web-cache-deception.md).

Chaining

An unkeyed input reflected into HTML/JS turns poisoning into stored XSS served to every client hitting that key - escalate the payload with hunt-xss. A reflected X-Forwarded-Host in a redirect or absolute link gives open redirect / resource swap to all users. Both raise impact from self-only to mass; prove reach on a benign key, then stop (see stop condition).

Evasion

When the input looks keyed or filtered: try header-name variants (X-Forwarded-Host vs X-Host vs Forwarded), duplicate/pollute the param so the cache keys one occurrence and the origin reads another, exploit cache-key normalization (case, trailing slash, %2f), and use a fat GET (body params on a GET) to smuggle the value past a keyed query string.

Show full SKILL.md (285 more words)Show less

Confirmation gate

Web cache poisoning is a blind / OOB-capable class: the win is a response served to OTHER clients, which you cannot observe from your own session alone.

NOT confirmation: your own cached response reflected back to you alone; a single response that might be per-user; an Age / X-Cache: hit change with no cross-session retrieval; the payload echoed in your own request.

IS confirmation: a poisoned or deceived response served to a DIFFERENT session and reproduced in a clean session (fresh profile, no cached state, cache-buster off); or an OOB callback to your unique Burp Collaborator / interactsh subdomain from a resource you injected into the cached page - a Collaborator-pointed unkeyed header confirms the poisoning reaches the cache and is loaded by other clients.

When you plant a blind/OOB payload, append a row to targets/<eng>/oob.md: | <token> | <sink url+param> | cache | <date> | waiting | | (columns: token | sink | class | planted | status | source; token = your unique Burp Collaborator / interactsh label). The recon-capture hook auto-correlates incoming callbacks to flip the row to HIT and SessionStart surfaces HITs; a HIT row in targets/<eng>/oob.md is the gate to scaffold the FIND. Do NOT claim a blind cache poisoning without cross-session proof or a HIT row.

Stop condition (traffic-affecting)

Per hunt-core, cache poisoning is a traffic-affecting primitive: poisoning the shared/production cache can serve malicious content to every real user who hits that key. Demonstrate on a benign, self-scoped cache key (a unique cache-buster or your own path) and STOP at proof. Do not mass-poison a shared key, and do not leave a live payload sitting in the production cache.

Severity

HIGH (stored XSS / redirect to all users, or PII disclosure via deception); CRITICAL if it yields mass account takeover; MEDIUM if self-only / weak impact.

Deadends

Append: - [ ] web-cache <host> -- key includes host+all reflective params; deception suffixes not cached (Cache-Control: private)

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt/hunt-cache of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Hunt Cache next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Cache compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Cache this skillEncod3d-Sec/TORCH329—~1.6kAutomated safety check: PassMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Hunt Cache

What does Hunt Cache do?

Web cache poisoning + cache deception hunting - unkeyed input poisoning, cache-key analysis, path-confusion deception, header/parameter cloaking. Hunt Cache is an agent skill from Encod3d-Sec/TORCH. Web cache poisoning + cache deception hunting - unkeyed input poisoning, cache-key analysis, path-confusion deception, header/parameter cloaking.

When should I use Hunt Cache?

Hunt Cache fits situations like: security work in your project.

How do I install Hunt Cache in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-cache -a claude-code`. Or copy the skill folder (skills/hunt/hunt-cache in Encod3d-Sec/TORCH) into .claude/skills/hunt-cache in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Cache in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-cache -a codex`. Or copy the skill folder (skills/hunt/hunt-cache in Encod3d-Sec/TORCH) into .agents/skills/hunt-cache in your project. Codex loads it when a task matches its description.

Can I use Hunt Cache in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill hunt-cache -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-cache, .gemini/skills/hunt-cache, .github/skills/hunt-cache and .opencode/skills/hunt-cache in your project.

What does Hunt Cache need to run?

Going by SKILL.md and its folder, Hunt Cache needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Hunt Cache access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hunt Cache safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Cache use?

Hunt Cache is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Cache use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Cache?

Skills that share tags, products or a category with Hunt Cache: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Cache?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.