Agent skill

Hunt Idor

by Encod3d-Sec in Encod3d-Sec/TORCH

IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…

MITAuto-check passedSecurity

Install Hunt Idor

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill hunt-idor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH hunt-idor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt/hunt-idor .claude/skills/hunt-idor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-idor
GitHub stars
329
Token cost
~2.6k tokens
SKILL.md length
1,235 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…

  • Works in 2 steps: The check is missing - test with B's… → The UUID is obtainable - find where it…
  • Broken access control
  • SKILL.md covers Wiki, Attack surface signals, Where the identifiers are and UUID: a two-part finding, plus 4 more sections
  • Calls curl and python3; needs USER_B_TOKEN

What it does

Hunt Idor is an agent skill from Encod3d-Sec/TORCH. IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and delete operations. Bounded ID sampling, never range sweeps. Wiki-first, FIND schema output. Trigger on IDOR, BOLA, broken access control, object level authorization, cross-tenant, "read another user's data", "swap the id", or any API path or parameter carrying a numeric ID, UUID, or account identifier.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities, Authorization and RBAC and GraphQL. It works with GraphQL. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Broken access control
  • Object level authorization
  • Read another users data
  • Parameter carrying a numeric ID

Example prompts

  • “read another user”
  • “swap the id”
  • “/hunt-idor”

Requirements

  • Python 3
  • A credential in USER_B_TOKEN

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. The check is missing - test with B's UUID, which you legitimately hold.
  2. The UUID is obtainable - find where it leaks.

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • USER_B_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt Idor loads about 2.6k tokens when it runs. Until then it costs about 127 tokens; SKILL.md has 1,235 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~127
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 1,235 words, ~2,597 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-idor/SKILL.md (or your agent's skills folder).
name
hunt-idor
description
IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and delete operations. Bounded ID sampling, never range sweeps. Wiki-first, FIND schema output. Trigger on IDOR, BOLA, broken access control, object level authorization, cross-tenant, "read another user's data", "swap the id", or any API path or parameter carrying a numeric ID, UUID, or account identifier.

Hunt: IDOR / Broken Object Level Authorization

Assumes hunt-core for the scope gate, two-account rule, confirmation gate, enumeration limits, stop conditions, wiki protocol, FIND output, and Deadends. Do not re-derive any of that here.

Wiki

qmd_query "IDOR BOLA insecure direct object reference access control" via wiki-search MCP

Hub: [[web-moc]] (live web index). Primary page: [[access-control]]. Payload arsenal: wiki/payloads/idor.md. Anchors: [[uuid-insecurities]] (v1-UUID timestamp/MAC when an object ID is a UUID rather than a sequential integer), [[jwt-attacks]] (chain a trusted sub/user_id claim to ATO, hand off to hunt-auth).

Attack surface signals

URL patterns: /api/v1/users/{id}, /invoices?id=, /reports/{uuid}/, /messages/{thread_id}, /admin/orgs/{org_id}/members

GraphQL: any query or mutation taking an id argument. Check for node(id: "...") global lookups - one endpoint reaching every object type, with per-type authorization frequently missing on at least one.

Rank before testing. Not all endpoints are equally likely:

  • Newest features - middleware follows codebase conventions; a feature written outside them misses it.
  • Bulk and export endpoints - one request, many objects, much higher severity per finding.
  • Anything carrying two identifiers - see the trusted-identifier test below.
  • Cross-service internal calls - the internal hop often carries no user context at all.
  • File and document access - frequently a separate host or CDN with no authorization beyond knowing the ID.
  • Non-GET verbs on read-looking endpoints - GET /orders/123 authorized, PATCH not.

Where the identifiers are

Check all of these; the least obvious are the least protected. Path segments, query parameters, request bodies (including nested objects), headers (X-User-Id, X-Account-Id, X-Tenant-Id), cookies, JWT claims, GraphQL variables, WebSocket messages, and file/CDN URLs.

Get B's identifiers from B. Log in as B and read them from B's own traffic, profile page, or JWT. Record in identities.md. Never obtain an identifier by incrementing until you find out whose it is - that is enumerating real users.

Decode opaque identifiers before assuming they are random. Base64 and hex frequently decode to a plain integer or a type:id pair. Where the ID is a hash, test whether it hashes something knowable (email, user ID, timestamp) and compute B's offline.

UUID: a two-part finding

A random UUID is not an authorization control, but it is a practical barrier. The finding becomes a chain:

  1. The check is missing - test with B's UUID, which you legitimately hold.
  2. The UUID is obtainable - find where it leaks.

Report both together. Part 1 alone gets triaged down as "requires an unguessable identifier."

Leak sources worth working: search and autocomplete endpoints, notification and activity feeds, team and member lists, verbose errors, notification emails, exported files, share and invite links, and objects you can read that reference objects you cannot.

Also verify the UUID is actually random - v1 encodes timestamp and MAC ([[uuid-insecurities]]), and hand-rolled implementations frequently emit sequential values dressed as UUIDs.

Methodology

Setup: two accounts per hunt-core. A owns, B attacks. Separate profiles.

Drive it through Burp for operator visibility. With A's request captured in Repeater or proxy history:

scripts/burp/idor-sweep.py <eng> <reqfile> --attacker-auth "Cookie: session=USER_B" --range 5

Sends owner-baseline / idor-test / bounded id sample through send_http1_request, diffs status and body, prints a verdict and a ready capture.sh burp PoC line. Honors no_bruteforce -> range 0. Do not raise --range above the hunt-core limits without operator approval.

For GUI-visible replay: create_repeater_tab for an A tab and a B tab, or send_to_intruder with a bounded number payload.

  1. Log in as A, browse every feature, note every ID - object, UUID, org, invoice, thread.
  2. Baseline both directions. A requests A's object. B requests B's object. Record status, length, body shape. You are testing against these, not against intuition.
  3. Cross-request: B requests A's object with B's session.
bash
# Baseline - A owns it
curl -s -H "Cookie: session=USER_A" https://target.com/api/v1/invoices/12345

# Cross-account - B attempts
curl -s -H "Cookie: session=USER_B" https://target.com/api/v1/invoices/12345
  1. Rule out legitimate access before claiming anything. Is the object shared with B, in a shared team, public, or org-visible? Check the UI as B. This is the single most common false positive in this class - an app with sharing features generates them constantly.
  2. Trusted-identifier test - run this on every endpoint carrying two identifiers. The highest value test in IDOR and the most frequently skipped. Make the session and the parameter disagree:
Session: account B
Body:    {"user_id": "<A's id>", "action": "..."}
  • Server acts on B -> identity derived from session, parameter ignored. Correct.
  • Server acts on A -> the parameter is trusted. IDOR, usually critical, fully attacker-controlled.
  • Server errors on mismatch -> it compares them. Correct, and evasion is the next step.

Apply the same to JWT claims: modify sub / user_id and see whether the server derives the acting user from the claim or looks it up. Trusted claim plus weak signature chains to arbitrary account takeover - hand off to hunt-auth.

  1. All verbs. GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS. Authorization applied per-method rather than per-resource is common.
  2. When the direct swap 403s, it is not closed. Parameter pollution (?id=A&id=B - the check and the fetch may read different occurrences), array wrapping ({"id":["A","B"]}), nested wrapping ({"user":{"id":"B"}}), path traversal in the identifier, encoding and case variation, version downgrade (/v1/ predates the middleware /v2/ has - the most reliable of these), and batch endpoints where per-item authorization is missing.
  3. Cross-tenant. Two accounts in different orgs. Categorically more severe than user-to-user inside one tenant: it breaks the isolation the product is sold on and implicates every customer. Say "cross-tenant" in the title - it changes who reads the report.
  4. GraphQL. Nested traversal is the signature bug - the entry point is authorized, the resolvers are not:
Show full SKILL.md (384 more words)Show less
graphql
query { me { organization { members { id email phone } } } }

Walk every edge from an authorized root. Also test node(id:) global lookups, aliases for parallel object access in one request, and mutations that introspection reveals but the UI never calls.

  1. Write and delete. More severe, more dangerous. Test on your own objects first to learn the request shape. Prefer reversible operations - changing B's display name proves it; deleting B's account proves the same and destroys your setup. Confirm from B's side. Never test a destructive write against an identifier you have not confirmed is B's.
  2. Bounded ID sampling - never a range sweep. Per hunt-core: five identifiers by default, twenty ceiling with approval, zero under no_bruteforce. Two or three adjacent IDs establish a sequential pattern; that is the whole proof. For scale, cite the total or pagination count, not retrieved records.
bash
# Bounded sample around a known ID - NOT a range sweep
known=48291
for i in $(seq $((known-2)) $((known+2))); do
  printf '%s ' "$i"
  curl -s -o /dev/null -w '%{http_code} %{size_download}\n' \
    -H "Authorization: Bearer USER_B_TOKEN" \
    "https://target.com/api/v1/orders/$i"
done
  1. Automate the breadth, verify every flag by hand. Session-replay tooling (Autorize-style) replaying every request under B's session while you browse as A turns this into a background pass. It produces false positives on endpoints returning identical public content - it narrows the queue, it does not produce findings.
  2. Distill when confirmed - reusable GraphQL IDOR or UUID-bypass technique, GENERIC, no client host: python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page techniques/web/access-control.md

Confirmation gate

NOT confirmation: a 200 with an empty or shell response; the object echoed back from your own request; B seeing an object that is shared, public, or org-visible; a response you have not compared against A's baseline; a write returning 200 with no state change verified from B's side.

IS confirmation: B's session returns A's data, matching A's own baseline response, with A's legitimate-access ruled out, reproduced in a clean session - and for writes, the change visible in B's UI.

Severity

Rated on the object, not the mechanism.

ObjectTypical
Session token, API key, reset tokencritical - direct ATO
Full user records with PIIcritical / high
Payment or billing detailcritical / high
Private documents, messageshigh
Account settings (write)high - enables takeover via email change
Internal identifiers onlylow - enables other attacks

Write outranks read at the same object. Unauthenticated outranks authenticated by a full band. Cross-tenant outranks cross-user. An unguessable identifier you cannot show leaking lowers it - chase the leak first.

Deadends

Append: - [ ] IDOR on <host> <endpoint> -- 403/404 cross-account, authorization enforced;
              tried pollution/array/verb/version downgrade

Record what you tried, not just that it failed. The next pass needs to know the boundary.

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt/hunt-idor of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Hunt Idor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Idor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Idor this skillEncod3d-Sec/TORCH329—~2.6kAutomated safety check: PassMIT
API Auditbriiirussell/cybersecurity-skills413—~2.8kAutomated safety check: NotesMIT
Moai Ref Secopsmodu-ai/moai-adk1.2k—~2.6kAutomated safety check: PassApache-2.0
Operate Sqlmapcyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.0
Access Control And Idormakifbaysal/tasktrooper112—~1.7kAutomated safety check: PassApache-2.0
Playwright Best Practicessanity-io/sanity6.4k7 repos~6.4kAutomated safety check: PassMIT

Similar skills

  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Moai Ref Secops

    modu-ai/moai-adk

    DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning…

    1.2k GitHub stars~2.6k tokensUpdated yesterday
    SecurityAuto-check passed
  • Operate Sqlmap

    cyberful/cyberful

    Use sqlmap to confirm and characterize suspected SQL injection with faithful requests and bounded evidence.

    135 GitHub stars~1.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Access Control And Idor

    makifbaysal/tasktrooper

    A skill your agent uses when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level…

    112 GitHub stars~1.7k tokensUpdated today
    SecurityAuto-check passed
  • Official

    A skill your agent uses when writing Playwright tests, fixing flaky tests, debugging failures, implementing Page Object Model, configuring CI/CD, optimizing performance, mocking APIs, handling…

    6.4k GitHub starsUsed in 7 repos~6.4k tokens
    Testing & QAAuto-check passed
  • Backend AI Guide

    lablup/backend.ai-webui

    Expert guide for Backend.AI distributed computing platform. An agent skill from lablup/backend.ai-webui.

    133 GitHub starsUsed in 1 repo~1.8k tokens
    Backend & APIsAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Hunt Idor

What does Hunt Idor do?

IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…. Hunt Idor is an agent skill from Encod3d-Sec/TORCH. IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and delete operations.

When should I use Hunt Idor?

Hunt Idor fits situations like: broken access control; object level authorization; read another users data; parameter carrying a numeric ID.

How do I install Hunt Idor in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-idor -a claude-code`. Or copy the skill folder (skills/hunt/hunt-idor in Encod3d-Sec/TORCH) into .claude/skills/hunt-idor in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Idor in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-idor -a codex`. Or copy the skill folder (skills/hunt/hunt-idor in Encod3d-Sec/TORCH) into .agents/skills/hunt-idor in your project. Codex loads it when a task matches its description.

Can I use Hunt Idor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill hunt-idor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-idor, .gemini/skills/hunt-idor, .github/skills/hunt-idor and .opencode/skills/hunt-idor in your project.

What does Hunt Idor need to run?

Going by SKILL.md and its folder, Hunt Idor needs the command-line tools its instructions call (curl and python3) and credentials named USER_B_TOKEN. Our summary lists: Python 3; A credential in USER_B_TOKEN.

Does Hunt Idor access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Hunt Idor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Idor use?

Hunt Idor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Idor use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Idor?

Skills that share tags, products or a category with Hunt Idor: API Audit (briiirussell/cybersecurity-skills, 413 stars), Moai Ref Secops (modu-ai/moai-adk, 1.2k stars), Operate Sqlmap (cyberful/cyberful, 135 stars) and Access Control And Idor (makifbaysal/tasktrooper, 112 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Idor?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.