Source

elementalsouls/claude-bughunter

83 skills · 11.7K combined installs

Skills from this source

#
Skill
Source
8W Activity
Installs
1
hunt-brute-force Hunt Missing/Weak Rate Limiting — login brute force, OTP/2FA brute force (10^6 keyspace), password-reset-token brute,…
elementalsouls/claude-bughunter
136
2
hunt-deserialization Hunt Insecure Deserialization — Java gadget chains (ysoserial), PHP object injection (phpggc), Python pickle RCE, .NE…
elementalsouls/claude-bughunter
136
3
hunt-open-redirect Hunt Open Redirect — all types including low-impact, chained to OAuth token theft → ATO, phishing chains. URL paramet…
elementalsouls/claude-bughunter
136
4
hunt-nosqli Hunt NoSQL Injection — MongoDB operator injection ($where, $regex, $gt, $ne), CouchDB, Redis command injection, auth …
elementalsouls/claude-bughunter
135
5
hunt-cors Hunt CORS Misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchore…
elementalsouls/claude-bughunter
134
6
hunt-nodejs Hunt Node.js specific vulnerabilities — Prototype Pollution → RCE chains (lodash/merge/assign), Express trust proxy m…
elementalsouls/claude-bughunter
134
7
hunt-session Hunt Session Management vulnerabilities — session fixation (no regeneration on login), insufficient invalidation on l…
elementalsouls/claude-bughunter
134
8
hunt-grpc Hunt gRPC vulnerabilities — server reflection enabled (enumerate all services/methods), missing authentication / meta…
elementalsouls/claude-bughunter
133
9
hunt-websocket Hunt WebSocket vulnerabilities — Cross-Site WebSocket Hijacking (CSWSH), missing/weak Origin validation on the WS han…
elementalsouls/claude-bughunter
133
10
hunt-dom Hunt client-side DOM vulnerabilities — DOM Clobbering (overwrite JS globals via HTML injection), PostMessage hijackin…
elementalsouls/claude-bughunter
132
11
hunt-k8s Hunt Kubernetes & Docker — API anonymous access, kubelet 10250 exec (SPDY/WebSocket, NOT plain POST) and the simpler …
elementalsouls/claude-bughunter
132
12
hunt-source-leak Hunt source code and build artifact leakage — JavaScript source maps (.js.map) reconstructing TypeScript/ES6 source, …
elementalsouls/claude-bughunter
132
13
hunt-tls-network Hunt TLS/SSL and DNS misconfigurations — missing HSTS (downgrade attack), weak cipher suites, expired/invalid certifi…
elementalsouls/claude-bughunter
132
14
hunt-cicd Hunt CI/CD pipeline vulnerabilities — GitHub Actions workflow injection (pull_request_target Pwnrequest + ${{ }}-into…
elementalsouls/claude-bughunter
131
15
hunt-host-header Hunt Host Header Injection — password reset poisoning → ATO, web cache poisoning via unkeyed Host/X-Forwarded-Host, r…
elementalsouls/claude-bughunter
129
16
hunt-lfi Hunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal — /etc/passwd read, log poisoning → …
elementalsouls/claude-bughunter
129
17
hunt-nextjs Hunt Next.js specific vulnerabilities — Server Actions arbitrary function execution, Middleware auth bypass via stati…
elementalsouls/claude-bughunter
129
18
hunt-springboot Hunt Spring Boot specific vulnerabilities — Actuator endpoints (heapdump, env, loggers, mappings, shutdown), Spring E…
elementalsouls/claude-bughunter
129
19
hunt-ldap Hunt LDAP Injection and XPath Injection — authentication bypass, blind char-by-char attribute exfiltration, AD user/g…
elementalsouls/claude-bughunter
128
20
hunt-laravel Hunt Laravel specific vulnerabilities — Debug mode leakage (APP_DEBUG=true exposes full stack trace + env vars), Lara…
elementalsouls/claude-bughunter
127
21
hunt-ntlm-info Hunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange.
elementalsouls/claude-bughunter
127
22
hunt-forgot-password Hunt Forgot Password / Account Recovery Authentication Flaws — 5 distinct patterns: (1) username enumeration via diff…
elementalsouls/claude-bughunter
82
23
hunt-spa-api Discover a single-page-app's hidden backend API from its public JS bundle, then test that API for broken access contr…
elementalsouls/claude-bughunter
82
24
hunt-clickjacking Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisi…
elementalsouls/claude-bughunter
81
25
hunt-shadow-api Hunt shadow / zombie / undocumented API surface (OWASP API9 Improper Inventory Management) — enumerate the full API v…
elementalsouls/claude-bughunter
81
26
hunt-captcha-bypass Hunt CAPTCHA Bypass — 6 distinct patterns: (1) CAPTCHA field simply omitted from the request (server-side validation …
elementalsouls/claude-bughunter
80
27
hunt-rag-vector Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) — persi…
elementalsouls/claude-bughunter
80
28
hunt-jwt-crypto Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker for…
elementalsouls/claude-bughunter
79
29
hunt-exceptional-conditions Hunt mishandling of exceptional conditions — feed an endpoint malformed/unexpected input (wrong type, broken JSON, ov…
elementalsouls/claude-bughunter
78
30
hunt-html-injection Hunt HTML Injection — user-supplied input is rendered as raw HTML in the response without sanitisation, allowing an a…
elementalsouls/claude-bughunter
78
31
ios-redteam-pipeline End-to-end iOS red-team pipeline — IPA acquisition (App Store extraction, TestFlight, enterprise/ad-hoc sideload), cl…
elementalsouls/claude-bughunter
78
32
recon-scope-triage Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noi…
elementalsouls/claude-bughunter
77
33
hunt-fintech-graphql Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card to…
elementalsouls/claude-bughunter
41
Page 2 · 83 total Previous