Agent skill

Browser Assisted Hunting

by langbyyi in langbyyi/CyberStrikeAI-SRC

浏览器交互式挖洞:登录态操作、双账号越权对比、SPA渲染取证、DOM XSS确认、验证码登录、前端隐藏功能绕过. An agent skill from langbyyi/CyberStrikeAI-SRC.

Apache-2.0Auto-check passedSecurity

Install Browser Assisted Hunting

skills CLI
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill browser-assisted-hunting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install langbyyi/CyberStrikeAI-SRC browser-assisted-hunting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/browser-assisted-hunting .claude/skills/browser-assisted-hunting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
browser-assisted-hunting
GitHub stars
129
Token cost
~434 tokens
SKILL.md length
146 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
Apache-2.0

At a glance

浏览器交互式挖洞:登录态操作、双账号越权对比、SPA渲染取证、DOM XSS确认、验证码登录、前端隐藏功能绕过. An agent skill from langbyyi/CyberStrikeAI-SRC.

  • Works in 4 steps: 双账号越权对比(最常用) → DOM XSS 确认 → 登录流与验证码 → …
  • CLI/HTTP evidence is insufficient and the target needs real browser interaction to confirm
  • SKILL.md covers 定位, 何时必须上浏览器, 标准打法 and 证据衔接(不可降级), plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Browser Assisted Hunting is an agent skill from langbyyi/CyberStrikeAI-SRC. 浏览器交互式挖洞:登录态操作、双账号越权对比、SPA渲染取证、DOM XSS确认、验证码登录、前端隐藏功能绕过。 Use when CLI/HTTP evidence is insufficient and the target needs real browser interaction to confirm.

Its SKILL.md is about 430 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities. The licence is Apache-2.0.

When your agent uses it

  • CLI/HTTP evidence is insufficient and the target needs real browser interaction to confirm
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/browser-assisted-hunting”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. 双账号越权对比(最常用)
  2. DOM XSS 确认
  3. 登录流与验证码
  4. 前端逻辑绕过

What it can do on your machine

Read from SKILL.md and the folder at commit 166ee1c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Browser Assisted Hunting loads about 434 tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 146 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~434

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from langbyyi/CyberStrikeAI-SRC at commit 166ee1c, republished under its Apache-2.0 licence (© langbyyi). 146 words, ~434 tokens.

Download SKILL.mdSave it as .claude/skills/browser-assisted-hunting/SKILL.md (or your agent's skills folder).
name
browser-assisted-hunting
description
浏览器交互式挖洞:登录态操作、双账号越权对比、SPA渲染取证、DOM XSS确认、验证码登录、前端隐藏功能绕过。 Use when CLI/HTTP evidence is insufficient and the target needs real browser interaction to confirm.
metadata.tags
SRC, 漏洞挖掘, 浏览器测试

定位

命令行与 HTTP 工具拿不到渲染后状态与交互反馈。当目标的漏洞需要真浏览器操作才能确认时用本 skill(依赖外部 MCP,如 Playwright)。它只补验证手段,不降低任何证据门槛;授权边界遵循 authorized-attack-scope。

何时必须上浏览器

场景命令行为什么不行浏览器怎么做
SPA 动态渲染源码无数据,接口运行时才生成browser_snapshot 读无障碍树,定位真实接口与元素
登录态多步交互登录流有 JS 挑战/跳转/加密表单填写走完登录,再操作目标功能
越权对比需两个独立会话 Cookie 环境双浏览器 context 隔离登录,互相重放
DOM XSS源码含 sink ≠ 执行渲染后读 DOM/console + 截图执行效果
CSRF 实操需浏览器真实携带 Cookie 跨站提交构造表单自动提交,观察副作用
前端隐藏功能hidden/disabled 元素命令行看不见snapshot 找到元素,绕过前端限制打后端

标准打法

1. 双账号越权对比(最常用)
  1. 开两个浏览器 context(Cookie 隔离),分别登录测试账号 A、B。
  2. A 中定位目标功能:订单/个人资料/文件下载/消息等,记下请求 URL 与参数。
  3. B 中重放:改 ID 参数直接导航或重新发起,读取渲染结果。
  4. B 能看到非 B 的数据即越权成立。证据:B 侧截图 + 快照关键节点 + 命中的 URL/参数。
2. DOM XSS 确认
  1. 注入点提交 payload 后等渲染完成。
  2. browser_snapshot 或执行 JS 读取 sink 处的实际值,确认 payload 进入且被解析执行。
  3. 截图执行效果(弹窗/样式变化/外带请求)。「源码里看得到 payload」不算证据,渲染后执行效果才算。
3. 登录流与验证码
  1. browser_type 填表单提交;遇验证码先截图。
  2. 截图传给 ddddocr 工具识别(ocr 文字码 / detect 点选坐标 / slide 滑块缺口),结果回填。
  3. 登录态建立后继续目标操作;登录成功本身可作为「auth_required」字段的实测依据。
4. 前端逻辑绕过
  1. snapshot 找 disabled/hidden 的按钮、被前端拦截的接口。
  2. 前端限制不代表后端校验:直接调用后端接口或修改元素状态后提交。
  3. 后端未校验即成立;证据取请求/响应差分,浏览器只是发现手段。

证据衔接(不可降级)

  • 浏览器工具调用记录即真实探测证据,record_vulnerability 可复现门认可。
  • 截图是给人看的补充,必须配结构化证据:请求 URL/参数 + 渲染后快照的关键内容。
  • 负结果也落 Fact:「浏览器实测 XX 无渲染执行 / 无越权」,防止重复验证。

降级

tool_search 查不到 browser_* 工具(未挂浏览器 MCP)时:退回 HTTP 工具 + 手动 Cookie 头模拟登录态;在 Fact 中标注「缺渲染态证据」,不虚构浏览器结果。

© langbyyi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/browser-assisted-hunting of langbyyi/CyberStrikeAI-SRC.

Open the folder on GitHubat commit 166ee1c

Compare with similar skills

Browser Assisted Hunting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Browser Assisted Hunting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Browser Assisted Hunting this skilllangbyyi/CyberStrikeAI-SRC129—~434Automated safety check: PassApache-2.0
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Strix Code Vulnerability Scanusestrix/strix68k—~1.1kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone

Similar skills

  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    68k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

    68k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed

More from langbyyi/CyberStrikeAI-SRC

All 13 skills in this repo
  • Burp MCP Vuln Check

    langbyyi/CyberStrikeAI-SRC

    Automate low-impact web vulnerability verification through Burp MCP.

    129 GitHub stars~3.1k tokensUpdated 3 days ago
    Auto-check passed
  • Authbypass Authentication Flaws

    langbyyi/CyberStrikeAI-SRC

    Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.

    129 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • HTTP Parameter Pollution

    langbyyi/CyberStrikeAI-SRC

    HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.

    129 GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Insecure Source Code Management

    langbyyi/CyberStrikeAI-SRC

    Source control and artifact exposure (.git, .svn, .hg, backups, .env).

    129 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check: notes
  • Type Juggling

    langbyyi/CyberStrikeAI-SRC

    PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC.

    129 GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed
  • Websocket Security

    langbyyi/CyberStrikeAI-SRC

    WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.

    129 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed

Categories

Questions about Browser Assisted Hunting

What does Browser Assisted Hunting do?

浏览器交互式挖洞:登录态操作、双账号越权对比、SPA渲染取证、DOM XSS确认、验证码登录、前端隐藏功能绕过. An agent skill from langbyyi/CyberStrikeAI-SRC. Browser Assisted Hunting is an agent skill from langbyyi/CyberStrikeAI-SRC. 浏览器交互式挖洞:登录态操作、双账号越权对比、SPA渲染取证、DOM XSS确认、验证码登录、前端隐藏功能绕过。 Use when CLI/HTTP evidence is insufficient and the target needs real browser interaction to confirm.

When should I use Browser Assisted Hunting?

Browser Assisted Hunting fits situations like: CLI/HTTP evidence is insufficient and the target needs real browser interaction to confirm; tasks that involve Web application vulnerabilities.

How do I install Browser Assisted Hunting in Claude Code?

Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill browser-assisted-hunting -a claude-code`. Or copy the skill folder (skills/browser-assisted-hunting in langbyyi/CyberStrikeAI-SRC) into .claude/skills/browser-assisted-hunting in your project. Claude Code loads it when a task matches its description.

How do I install Browser Assisted Hunting in Codex?

Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill browser-assisted-hunting -a codex`. Or copy the skill folder (skills/browser-assisted-hunting in langbyyi/CyberStrikeAI-SRC) into .agents/skills/browser-assisted-hunting in your project. Codex loads it when a task matches its description.

Can I use Browser Assisted Hunting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbyyi/CyberStrikeAI-SRC --skill browser-assisted-hunting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/browser-assisted-hunting, .gemini/skills/browser-assisted-hunting, .github/skills/browser-assisted-hunting and .opencode/skills/browser-assisted-hunting in your project.

What does Browser Assisted Hunting need to run?

SKILL.md names no scripts, command-line tools or credentials: Browser Assisted Hunting is instructions for the agent only.

Does Browser Assisted Hunting access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Browser Assisted Hunting safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Browser Assisted Hunting use?

Browser Assisted Hunting is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Browser Assisted Hunting use?

About 434 tokens (SKILL.md is roughly 1.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Browser Assisted Hunting?

Skills that share tags, products or a category with Browser Assisted Hunting: Security And Hardening (penpot/penpot, 61k stars), Security Auditor (eigent-ai/eigent, 15k stars), Security Review (jewbetcha/opentrace, 116 stars) and Strix Code Vulnerability Scan (usestrix/strix, 68k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Browser Assisted Hunting?

langbyyi (a GitHub user) maintains it in langbyyi/CyberStrikeAI-SRC, which has 129 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 7, 2026.

Source: langbyyi/CyberStrikeAI-SRC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.