Agent skill

Unauth Path Key Hunt

by zhaji2333 in zhaji2333/CkSKILLS

当未授权/零身份测试但路径不在主站 JS、禁止依赖登录 Network 截图、独立 H5/旧域名 NXDOMAIN/品牌迁域、兄弟域或同 IP Host 漏路径、网关 405 或 data 空数组、getRsaKey/JSEncrypt/前端加密被当成鉴权时调用。负责零身份公开面还原路径与密钥、响应指纹分流、加密证伪、迁域复查。JS 拆包见 recon-js-analysis;角色/IDOR…

MITAuto-check passedSecurity

Install Unauth Path Key Hunt

skills CLI
$ npx skills add zhaji2333/CkSKILLS --skill unauth-path-key-hunt -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zhaji2333/CkSKILLS unauth-path-key-hunt --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zhaji2333/CkSKILLS.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/unauth-path-key-hunt .claude/skills/unauth-path-key-hunt && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
unauth-path-key-hunt
GitHub stars
115
Token cost
~1.4k tokens
SKILL.md length
568 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

当未授权/零身份测试但路径不在主站 JS、禁止依赖登录 Network 截图、独立 H5/旧域名 NXDOMAIN/品牌迁域、兄弟域或同 IP Host 漏路径、网关 405 或 data 空数组、getRsaKey/JSEncrypt/前端加密被当成鉴权时调用。负责零身份公开面还原路径与密钥、响应指纹分流、加密证伪、迁域复查。JS 拆包见 recon-js-analysis;角色/IDOR…

  • Works in 5 steps: 发现阶段禁止把「已登录… → 主站 JS 没有 ≠ 接口不存在。 → 客户端能拿到的 RSA/AES/uuid ≠ 鉴权。 → …
  • Tasks that involve Authorization and RBAC
  • SKILL.md covers 何时调用, 与其它技能分工, 铁律 and P0 零身份约束, plus 10 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Unauth Path Key Hunt is an agent skill from zhaji2333/CkSKILLS. 当未授权/零身份测试但路径不在主站 JS、禁止依赖登录 Network 截图、独立 H5/旧域名 NXDOMAIN/品牌迁域、兄弟域或同 IP Host 漏路径、网关 405 或 data 空数组、getRsaKey/JSEncrypt/前端加密被当成鉴权时调用。负责零身份公开面还原路径与密钥、响应指纹分流、加密证伪、迁域复查。JS 拆包见 recon-js-analysis;角色/IDOR 见 auth-access-control;路径已知后的全方法/BOLA 见 api-protocol-security。

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Authorization and RBAC and Web application vulnerabilities. The repository describes itself as: 基于 Claude Code / Codex 的 SRC 漏洞挖掘 Agent 技能体系 —— 将顶尖安全研究员的方法论沉淀为可调度、可复用的 Skill 知识资产。 The licence is MIT.

When your agent uses it

  • Tasks that involve Authorization and RBAC
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/unauth-path-key-hunt”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 发现阶段禁止把「已登录 Network」当路径出处。截图只作假设,公开面复原才是证据。
  2. 主站 JS 没有 ≠ 接口不存在。
  3. 客户端能拿到的 RSA/AES/uuid ≠ 鉴权。
  4. SPA 的 404 不是接口的 404。没到失败升级 L4 不准写「无此接口」。
  5. 旧 H5 / 旧 Host 下线 ≠ 后端方法下线。

What it can do on your machine

Read from SKILL.md and the folder at commit 482fe78. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Unauth Path Key Hunt loads about 1.4k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 568 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zhaji2333/CkSKILLS at commit 482fe78, republished under its MIT licence (© zhaji2333). 568 words, ~1,450 tokens.

Download SKILL.mdSave it as .claude/skills/unauth-path-key-hunt/SKILL.md (or your agent's skills folder).
name
unauth-path-key-hunt
description
当未授权/零身份测试但路径不在主站 JS、禁止依赖登录 Network 截图、独立 H5/旧域名 NXDOMAIN/品牌迁域、兄弟域或同 IP Host 漏路径、网关 405 或 data 空数组、getRsaKey/JSEncrypt/前端加密被当成鉴权时调用。负责零身份公开面还原路径与密钥、响应指纹分流、加密证伪、迁域复查。JS 拆包见 recon-js-analysis;角色/IDOR 见 auth-access-control;路径已知后的全方法/BOLA 见 api-protocol-security。

unauth-path-key-hunt — 零身份公开面:路径与密钥猎杀

编排型 skill。只解决「没有后台账号、路径不在当前前端时,如何独立还原接口并证伪加密=鉴权」。不替代 JS 拆包、越权矩阵、API 全方法。

何时调用

  • 未授权 / 攻击者没有该业务账号(纯零身份)
  • 路径不在主站 JS;用户要求不要用登录 Network 截图当发现源
  • 独立 H5、旧子域 NXDOMAIN、品牌迁域(旧 Host 301/消失)
  • 兄弟域、同 IP、--resolve 换 Host 漏出路径
  • 网关 405 Method Not Allowed、200 data:[]、短文案「链接不存在」
  • getRsaKey / JSEncrypt / SM2 / 前端 AES,怀疑只是传输混淆

不要调用(交给别人)

  • 攻击面不清、要广撒网拆 webpack / 脏收集 → recon-js-analysis
  • 路径已通,打角色/IDOR/JWT/验证码 → auth-access-control
  • 路径已通,全方法、BOLA、Swagger、走私 → api-protocol-security
  • 调试面板/中间件/对象存储未授权 → cloud-infra-supply-chain
  • 路径在 APK/小程序包里 → android-security-audit / miniprogram-security
  • 已验证要成稿 → report

与其它技能分工

怀疑隐藏未授权
    │
    ▼
unauth-path-key-hunt     找 Host/路径/钥,证伪加密
    ├─ 拆 webpack / 脏收集 / 提字符串     → recon-js-analysis
    ├─ 路径已通,角色墙 / IDOR            → auth-access-control
    ├─ 路径已通,全方法 / 旧版 / 网关协议  → api-protocol-security
    ├─ 路径在包里                         → android / miniprogram
    └─ 已验证成稿                         → report

拆 JS、Wayback、Packer 的细则以 recon-js-analysis 为准,此处不重复。 跨轮线索落盘以 hunt-clueboard 为准:开工先读 hunts/<目标>/CLUEBOARD.md,P2 指纹/405/[]/迁域结论当轮写回,禁止只写在对话里。

铁律

  1. 发现阶段禁止把「已登录 Network」当路径出处。截图只作假设,公开面复原才是证据。
  2. 主站 JS 没有 ≠ 接口不存在。
  3. 客户端能拿到的 RSA/AES/uuid ≠ 鉴权。
  4. SPA 的 404 不是接口的 404。没到失败升级 L4 不准写「无此接口」。
  5. 旧 H5 / 旧 Host 下线 ≠ 后端方法下线。

P0 零身份约束

允许的发现源: 未登录 HTML/JS/map;CT / urlscan / Wayback / GitHub;兄弟域与同 IP;301 Location;公开文档;未登录可下的 APP/小程序包。

不允许当发现源: 业务账号登录后的 DevTools;报告截图里的 URL(降级为待验证假设)。

口令:截图里的路径 = 假设;公开面复原 = 证据。


P1 入口地图

分清四类 Host,标 DNS/IP,不要只盯主域:

类典型下一步
C 端壳主站 / m / 品牌新域 Next/Vue在此搜路径常失败,记录后换场
API 网关appgw / apigw / qr / gatewayP2 指纹,不要当 SPA 扫目录
独立业务 H5invoice / vat / asp / mag / 活动 CDN优先拆 JS、打 /gp /mag 等前缀
后台/SSOpassport / admin / 服务商域记下 sid;零身份只证「墙在哪」

品牌新域、301 目标必须列入地图。

通过门: 至少标出「C 端壳 / 疑似网关 / 疑似业务 H5」三类。


P2 响应指纹(禁止 -L 跟着 302 再看 body)

记录四元组:状态码 / Content-Type / Server / body 形态。

指纹含义动作
SPA HTML 404(Next X-Powered-By,几十 KB index)前端路由吞路径,不是这个后端换 Host
网关 JSON:no api / Route Not Found / divide: selector网关活着,这条 route 没挂换 Host 或前缀
业务 JSON:success/code/message,path 出现在 body真应用进入 P4/P5
短 body 业务文案(「链接不存在」)vs 统一 404 页路径存在、资源不存在保留前缀,补 module/method
302 → SSO有鉴权墙,不是「没有服务」记下 Location 的 sid/应用名
405 Request method 'GET' not supported控制器在,方法不对立刻 POST
200 + data:[]已进控制器,只是没命中数据补参数/加密/字段名
同 IP 换 Host → 403 / 404 Route Not Found虚拟主机隔离继续找对的 ServerName

通过门: 每个候选路径都归入上表。禁止再写「404 所以没有」。


P3 路径发现五源(并行)

优先级从「更像零身份攻击者」到「更脏」。webpack/脏收集操作见 recon-js-analysis。

源做什么通过信号
1 现网 JS首页、buildManifest、异步 chunk、baseURL路径或方法名字符串有公开出处
2 历史旁路urlscan / Wayback / CT / 第三方脚本引用的 Host旧 URL、CDN 活动页、发票/售后等业务词
3 兄弟域 + 同 IP对未解析旧 Host --resolve 到网关 IP对 Host=业务 200;错 Host=网关 404/403
4 命名习惯有第一段后续猜:/{svc}/{module}/{method}/{id}、/gp/{ctx}/{action}、ForFree/open/anon405 或业务 JSON
5 包C 端 Web 没有的方法名交给 android / miniprogram,产物回到本 skill 打 Host

主站源1 为空是常态,进入源2/3,不要结案。

通过门: 路径字符串能指出公开出处(JS 行 / urlscan / 兄弟域指纹)。没有出处仍是假设。


P4 密钥还原与鉴权证伪

目标不是解密,是判断密码学有没有替代鉴权。

从 JS 必须对齐 6 项(提取步骤走 recon-js-analysis):

  1. 取钥接口(getRsaKey / getPublicKey / ticket)
  2. 算法与填充(JSEncrypt 默认 PKCS#1 v1.5)
  3. POST 字段名(响应里的 uuid 可能要改名为 rsaUuid)
  4. 密钥生命周期(多次 GET 是否同一 uuid/公钥 → 静态密钥 ID)
  5. 加密范围(只加密关键字,还是整包)
  6. 无 Cookie 能否取钥

口令:

  • 客户端能取的「密钥」,对攻击者不是密钥。
  • 加密查询字 ≠ 证明你是谁。
  • 字段名以 JS 为准,猜错会假阴性(空数组)。
Show full SKILL.md (212 more words)Show less
T0–T3 对照(详细越权矩阵见 auth-access-control)
编号条件仍业务成功则
T0无 Cookie、无 Authorization未授权
T1错误/过期 Token鉴权没校验
T2有登录但无该业务角色SSO 与 ACL 分离,记录「能进门不能办事」
T3去掉加密或改错绑定字段加密是协议还是装饰

T0 成功 + 敏感字段 → 未授权成立。T0 仅 302/ACL、业务接口已下线 → 路径存在但利用链断,分开写。


P5 字段对齐(空结果最易误判)

  1. GET 目标方法 → 吃 405,改 POST
  2. POST {} → data:[] 说明已进控制器
  3. 明文关键字 / 错字段名 / 对字段名+密文 三组对照
  4. 从同类加密接口抄字段名(改密用 rsaUuid,查询多半同一个)

示例(字段名错了会像没洞):

body常见结果
{}200 [](无鉴权)
{title: 密文}[](缺绑定)
{title, uuid}[](名错)
{title, rsaUuid}非空列表

通过门: 至少一种变体能把 [] 变成非空,或错误信息给出参数名。否则只写「接口暴露,危害未证实」。

路径对齐之后的全方法/BOLA/分页遍历交给 api-protocol-security。


P6 迁域复查

旧站下线必须四问:

  1. 旧 Host 是 NXDOMAIN 还是 301?301 的 Location 是新战场。
  2. 新品牌域有没有把 API 一起搬走,还是只搬了 C 端壳?
  3. 同 IP 上哪个 ServerName 还在反代这套前缀(/gp /mag)?
  4. 前端 chunk 删了方法名,网关上方法还在不在?(405/200 比 JS 诚实)

P7 失败升级

没到 L4 不准写「无此接口」:

Level动作
L1主站 JS 全文搜
L2异步 chunk / 独立 H5 JS
L3兄弟域、CDN、urlscan、CT
L4网关 Host 探测 + 405 / 业务 JSON
L5换入口:APP、小程序、开放文档
L6旧方法名 + 新 Host
L7Wayback 旧 JS 的 baseURL 打现网

P8 危害落地与输出

  • 列表类:公开公司简称作关键字;统计条数与含账号/税号字段数;正文只出脱敏样本。
  • ID 类:先解决 ID 从哪来(公开格式、C 端自己的单、枚举)。没有合法 ID 不能宣称可打任意用户。
  • 复现用 curl,证明请求无登录 Cookie。
  • 覆盖度必填:✅已测 / ❌未测 / 🔄变种 / 💡关联;同步写进线索板第 7 节。
  • 评估表走总纲第 5 节。成稿走 report(只读板上「已证实」行)。

通用决策句

  1. 主站没有,去兄弟域和历史域。
  2. SPA 的 404 不是接口的 404。
  3. 「链接不存在」/405/空数组,往往比统一 404 更值钱。
  4. 路径跟 Host 走,不跟品牌官网走。
  5. 前端能取的 RSA/AES/uuid 只是协议,不是登录。
  6. 加密字段名以 JS 为准,猜错就假阴性。
  7. H5 下线只删了壳,旧 method 可能还在网关上。
  8. 截图证明利用,公开面证明发现。

类型对照:角色隔离后台(C 端无路径)/ 专项独立 H5 / 换皮迁域 / 前端已删后端未下。四类可叠加。


修复(未授权接口)

  • 网关统一鉴权;ForFree/open/anon 默认视为危险命名,必须有身份或强频控+最小字段。
  • 前端加密不能替代登录;取钥接口同样要鉴权或只对已登录会话下发。
  • 下线 H5 必须同时下线路由/控制器,不能只删 DNS。
  • 企业抬头等财务身份禁止对未登录返回完整银行账号。

© zhaji2333, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/unauth-path-key-hunt of zhaji2333/CkSKILLS.

Open the folder on GitHubat commit 482fe78

Compare with similar skills

Unauth Path Key Hunt next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Unauth Path Key Hunt compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Unauth Path Key Hunt this skillzhaji2333/CkSKILLS115—~1.4kAutomated safety check: PassMIT
Security Reviewlangfuse/langfuse36k—~1.4kAutomated safety check: PassCustom licence
Security ConvexIgorWarzocha/Opencode-Workflows122—~3.1kAutomated safety check: PassNone
Access Control And Idormakifbaysal/tasktrooper112—~1.7kAutomated safety check: PassApache-2.0
Hunt IdorEncod3d-Sec/TORCH329—~2.6kAutomated safety check: PassMIT
Security And Hardeningdzhalaevd/Donatello135—~5.1kAutomated safety check: NotesApache-2.0

Similar skills

  • Security Review

    langfuse/langfuse

    Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.

    36k GitHub stars~1.4k tokensUpdated today
    SecurityAuto-check passed
  • Security Convex

    IgorWarzocha/Opencode-Workflows

    Review Convex security audit patterns for authentication and authorization.

    122 GitHub stars~3.1k tokensUpdated 8 mo ago
    SecurityAuto-check passed
  • Access Control And Idor

    makifbaysal/tasktrooper

    A skill your agent uses when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level…

    112 GitHub stars~1.7k tokensUpdated today
    SecurityAuto-check passed
  • Hunt Idor

    Encod3d-Sec/TORCH

    IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…

    329 GitHub stars~2.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security And Hardening

    dzhalaevd/Donatello

    Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.

    135 GitHub stars~5.1k tokensUpdated 7 days ago
    SecurityAuto-check: notes
  • Php Yii Audit

    0xShe/PHP-Code-Audit-Skill

    Yii 框架特效安全审计工具。针对 Yii(通常指 Yii2)访问控制(AccessControl/RBAC)、CSRF、输入过滤规则、输出编码策略、URL/重定向安全等进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/XSS/CFG/LOGIC 等)。

    402 GitHub starsUsed in 1 repo~528 tokens
    SecurityAuto-check passed

More from zhaji2333/CkSKILLS

All 15 skills in this repo
  • Apk Reversing

    zhaji2333/CkSKILLS

    当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是…

    115 GitHub stars~1.7k tokensUpdated 26 days ago
    Auto-check passed
  • Asc Fast Hunt

    zhaji2333/CkSKILLS

    当需要在不对 APK 全量反编译的前提下秒级定位硬编码密钥/签名函数/隐藏接口/调试后门,或 APK 过大(100MB)JADX 全量反编译过慢、内存吃紧,或脱壳产物(裸 dex)需要快速检索,或只想先读一下 Manifest 组件面/权限清单时调用。负责基于 Droid ASC 的零预处理快速定位(findrefs 全局交叉引用搜索 + getclass 按需反编译 + Manifest…

    115 GitHub stars~3.3k tokensUpdated 26 days ago
    Auto-check passed
  • Business Logic Race

    zhaji2333/CkSKILLS

    当目标存在支付/下单/退款/提现/转账/优惠券/积分/红包/会员/订阅/审批/库存/抽奖等业务功能,或发现状态可跳变、金额参数可控、并发可重放时调用。负责业务状态机建模、金额篡改、订单状态跳变、竞态条件与重放攻击深度挖掘。

    115 GitHub stars~466 tokensUpdated 26 days ago
    Auto-check passed
  • AI LLM Agent Security

    zhaji2333/CkSKILLS

    当目标为 LLM 应用/Chatbot/智能客服/AI 助手/Copilot/Agent/RAG 知识库/多模态模型,或发现用户输入进入大模型提示、工具调用、知识库检索、对话记忆、文件解析,或需要测试提示词注入/越狱逃逸/System Prompt 泄露/训练数据与敏感信息泄露/RAG 检索污染/Agent 记忆污染/工具滥用与命令执行/SSRF/沙箱逃逸时调用。负责 OWASP LLM…

    115 GitHub stars~4.7k tokensUpdated 26 days ago
    Auto-check: warnings
  • Hunt Clueboard

    zhaji2333/CkSKILLS

    当开始挖新目标、换会话/压缩后续挖、用户说线索板/写板/读板/建板,或信息收集、反编译、JS/接口线索需要跨轮保留时调用。负责为当前系统维护一份 Markdown 线索板(读→挖→写回),不负责拆 webpack、打越权或成稿。模板见同目录 CLUEBOARD.template.md。

    115 GitHub stars~606 tokensUpdated 26 days ago
    Auto-check passed
  • Cloud Infra Supply Chain

    zhaji2333/CkSKILLS

    当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。

    115 GitHub stars~688 tokensUpdated 26 days ago
    Auto-check: warnings

Questions about Unauth Path Key Hunt

What does Unauth Path Key Hunt do?

当未授权/零身份测试但路径不在主站 JS、禁止依赖登录 Network 截图、独立 H5/旧域名 NXDOMAIN/品牌迁域、兄弟域或同 IP Host 漏路径、网关 405 或 data 空数组、getRsaKey/JSEncrypt/前端加密被当成鉴权时调用。负责零身份公开面还原路径与密钥、响应指纹分流、加密证伪、迁域复查。JS 拆包见 recon-js-analysis;角色/IDOR…. Unauth Path Key Hunt is an agent skill from zhaji2333/CkSKILLS.

When should I use Unauth Path Key Hunt?

Unauth Path Key Hunt fits situations like: tasks that involve Authorization and RBAC; tasks that involve Web application vulnerabilities.

How do I install Unauth Path Key Hunt in Claude Code?

Run `npx skills add zhaji2333/CkSKILLS --skill unauth-path-key-hunt -a claude-code`. Or copy the skill folder (.agents/skills/unauth-path-key-hunt in zhaji2333/CkSKILLS) into .claude/skills/unauth-path-key-hunt in your project. Claude Code loads it when a task matches its description.

How do I install Unauth Path Key Hunt in Codex?

Run `npx skills add zhaji2333/CkSKILLS --skill unauth-path-key-hunt -a codex`. Or copy the skill folder (.agents/skills/unauth-path-key-hunt in zhaji2333/CkSKILLS) into .agents/skills/unauth-path-key-hunt in your project. Codex loads it when a task matches its description.

Can I use Unauth Path Key Hunt in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zhaji2333/CkSKILLS --skill unauth-path-key-hunt -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/unauth-path-key-hunt, .gemini/skills/unauth-path-key-hunt, .github/skills/unauth-path-key-hunt and .opencode/skills/unauth-path-key-hunt in your project.

What does Unauth Path Key Hunt need to run?

SKILL.md names no scripts, command-line tools or credentials: Unauth Path Key Hunt is instructions for the agent only.

Does Unauth Path Key Hunt access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Unauth Path Key Hunt safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Unauth Path Key Hunt use?

Unauth Path Key Hunt is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Unauth Path Key Hunt use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Unauth Path Key Hunt?

Skills that share tags, products or a category with Unauth Path Key Hunt: Security Review (langfuse/langfuse, 36k stars), Security Convex (IgorWarzocha/Opencode-Workflows, 122 stars), Access Control And Idor (makifbaysal/tasktrooper, 112 stars) and Hunt Idor (Encod3d-Sec/TORCH, 329 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Unauth Path Key Hunt?

zhaji2333 (a GitHub user) maintains it in zhaji2333/CkSKILLS, which has 115 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on September 15, 2026.

Source: zhaji2333/CkSKILLS on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.