{"skill":{"slug":"elementalsouls-hunt-auth-bypass","name":"hunt-auth-bypass","description":"Hunting skill for auth bypass vulnerabilities. Built from 12 public bug bounty reports across SAML XSW / parser-differential (GitHub Enterprise CVE-2025-25291/25292), SAML signature stripping (Uber, Rocket.Chat, samlify CVE-2025-47949), SAML domain enforcement bypass via control characters (HackerOne 2024), partner-portal cross-IdP assertion reuse (Slack), WordPress XMLRPC bypassing SSO (Uber), JWT alg-confusion HS256/RS256 (Jitsi), JWT signature-validation skip (Linktree, Newspack), and token-audience confusion (Argo CD CVE-2023-22482). For standalone JWT signature/crypto forging (alg:none, key confusion, kid/jku) see hunt-jwt-crypto; this skill covers JWT only inside SSO/SAML/token-trust bypass chains. SAML assertion-layer attacks (XSW, comment injection, signature stripping, XXE-in-assertion) are owned by hunt-saml; this skill owns the broader cross-protocol auth-bypass taxonomy. Use when hunting auth bypass — see the Legacy-Protocol Matrix for branded-UI vs legacy-endpoint patterns","repository":"https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-auth-bypass"},"recommended_command":"npx skills add elementalsouls/Claude-BugHunter --skill hunt-auth-bypass","install_targets":[{"id":"openagentskill-cli","label":"CLI","title":"OpenAgentSkill CLI","kind":"command","value":"npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.3.0/openagentskill-0.3.0.tgz add elementalsouls-hunt-auth-bypass","description":"Resolve policy, run the source installer safely, and report a verified install receipt.","copyLabel":"Copy command"},{"id":"codex","label":"Codex","title":"Codex install prompt","kind":"agent-prompt","value":"Install the \"hunt-auth-bypass\" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-auth-bypass. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Hunting skill for auth bypass vulnerabilities. Built from 12 public bug bounty reports across SAML XSW / parser-differential (GitHub Enterprise CVE-2025-25291/25292), SAML signature stripping (Uber, Rocket.Chat, samlify CVE-2025-47949), SAML domain enforcement bypass via control characters (HackerOne 2024), partner-portal cross-IdP assertion reuse (Slack), WordPress XMLRPC bypassing SSO (Uber), JWT alg-confusion HS256/RS256 (Jitsi), JWT signature-validation skip (Linktree, Newspack), and token-audience confusion (Argo CD CVE-2023-22482). For standalone JWT signature/crypto forging (alg:none, key confusion, kid/jku) see hunt-jwt-crypto; this skill covers JWT only inside SSO/SAML/token-trust bypass chains. SAML assertion-layer attacks (XSW, comment injection, signature stripping, XXE-in-assertion) are owned by hunt-saml; this skill owns the broader cross-protocol auth-bypass taxonomy. Use when hunting auth bypass — see the Legacy-Protocol Matrix for branded-UI vs legacy-endpoint patterns After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"elementalsouls-hunt-auth-bypass\",\"task\":\"Install hunt-auth-bypass\",\"agent\":\"codex\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.","description":"Give Codex a repo-aware install prompt when the skill is not available through a local CLI.","copyLabel":"Copy prompt"},{"id":"claude-code","label":"Claude Code","title":"Claude Code skill prompt","kind":"agent-prompt","value":"Add \"hunt-auth-bypass\" as a Claude Code skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-auth-bypass. Inspect the skill instructions, place the reusable skill files in the appropriate local skills location for this project, and report the activation steps. Skill purpose: Hunting skill for auth bypass vulnerabilities. Built from 12 public bug bounty reports across SAML XSW / parser-differential (GitHub Enterprise CVE-2025-25291/25292), SAML signature stripping (Uber, Rocket.Chat, samlify CVE-2025-47949), SAML domain enforcement bypass via control characters (HackerOne 2024), partner-portal cross-IdP assertion reuse (Slack), WordPress XMLRPC bypassing SSO (Uber), JWT alg-confusion HS256/RS256 (Jitsi), JWT signature-validation skip (Linktree, Newspack), and token-audience confusion (Argo CD CVE-2023-22482). For standalone JWT signature/crypto forging (alg:none, key confusion, kid/jku) see hunt-jwt-crypto; this skill covers JWT only inside SSO/SAML/token-trust bypass chains. SAML assertion-layer attacks (XSW, comment injection, signature stripping, XXE-in-assertion) are owned by hunt-saml; this skill owns the broader cross-protocol auth-bypass taxonomy. Use when hunting auth bypass — see the Legacy-Protocol Matrix for branded-UI vs legacy-endpoint patterns After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"elementalsouls-hunt-auth-bypass\",\"task\":\"Install hunt-auth-bypass\",\"agent\":\"claude-code\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.","description":"Use this prompt to ask Claude Code to add the skill and explain the local activation steps.","copyLabel":"Copy prompt"},{"id":"cursor","label":"Cursor","title":"Cursor rule prompt","kind":"agent-prompt","value":"Turn \"hunt-auth-bypass\" from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-auth-bypass into a reusable Cursor project rule or agent instruction. Preserve the core workflow, adapt paths to this repo, and keep the rule scoped to tasks where it is relevant. Skill purpose: Hunting skill for auth bypass vulnerabilities. Built from 12 public bug bounty reports across SAML XSW / parser-differential (GitHub Enterprise CVE-2025-25291/25292), SAML signature stripping (Uber, Rocket.Chat, samlify CVE-2025-47949), SAML domain enforcement bypass via control characters (HackerOne 2024), partner-portal cross-IdP assertion reuse (Slack), WordPress XMLRPC bypassing SSO (Uber), JWT alg-confusion HS256/RS256 (Jitsi), JWT signature-validation skip (Linktree, Newspack), and token-audience confusion (Argo CD CVE-2023-22482). For standalone JWT signature/crypto forging (alg:none, key confusion, kid/jku) see hunt-jwt-crypto; this skill covers JWT only inside SSO/SAML/token-trust bypass chains. SAML assertion-layer attacks (XSW, comment injection, signature stripping, XXE-in-assertion) are owned by hunt-saml; this skill owns the broader cross-protocol auth-bypass taxonomy. Use when hunting auth bypass — see the Legacy-Protocol Matrix for branded-UI vs legacy-endpoint patterns After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"elementalsouls-hunt-auth-bypass\",\"task\":\"Install hunt-auth-bypass\",\"agent\":\"cursor\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.","description":"Use this when installing as Cursor project rules or reusable agent instructions.","copyLabel":"Copy prompt"}],"install_receipt":{"endpoint":"https://www.openagentskill.com/api/agent/outcome","method":"POST","idempotency":"event_id is unique; retries update the same receipt","count_rule":"verified installs require install_used=true and outcome=success","example":{"event_id":"install_<unique-id>","skill_slug":"elementalsouls-hunt-auth-bypass","task":"Install hunt-auth-bypass","agent":"codex","outcome":"success","install_used":true}},"safety_gate":{"tier":"blocked","label":"Blocked for auto-install","badge":"BLOCKED","auto_install_policy":"block","auto_install_allowed":false,"human_review_required":true,"blocked":true,"recommended_action":"Do not auto-install. Inspect the source, dependencies, and permission surface first.","reasons":["Metadata combines secrets access with shell or command execution","High-risk permission hints: Shell or command execution, Secrets or environment access"]},"agent_prompt":"Install the \"hunt-auth-bypass\" agent skill only after reviewing the OpenAgentSkill profile and source repository. Safety gate: Blocked for auto-install (block). Start with https://www.openagentskill.com/skills/elementalsouls-hunt-auth-bypass, inspect the trust and audit notes, then use the recommended install handoff: npx skills add elementalsouls/Claude-BugHunter --skill hunt-auth-bypass. After installation, summarize changed files, required setup, and a minimal verification result before using the skill for real work. Report the verified result to https://www.openagentskill.com/api/agent/outcome using a unique event_id, skill_slug=elementalsouls-hunt-auth-bypass, install_used=true, and outcome=success or failed.","safety_checklist":["Safety gate: Blocked for auto-install. Policy: block.","Do not auto-install. Inspect the source, dependencies, and permission surface first.","Review the repository and license before running third-party code.","Prefer a sandbox or isolated project when testing a new skill.","Start with the recommended command, then inspect generated files before committing changes.","Do not execute external side effects, payments, account changes, or credentialed actions without explicit user approval."],"verification_steps":["Open the skill documentation or SKILL.md and identify required setup.","Run the smallest safe example for the target task.","Confirm outputs match the task before allowing broader agent use.","Record any missing credentials, policy risks, or manual approvals needed."],"do_not_auto_install_when":["The repository or license cannot be reviewed.","The skill requires broad credentials or production account access.","The task involves regulated, private, or high-impact data without user approval."],"urls":{"web":"https://www.openagentskill.com/skills/elementalsouls-hunt-auth-bypass","api":"https://www.openagentskill.com/api/agent/skills/elementalsouls-hunt-auth-bypass","install_api":"https://www.openagentskill.com/api/skills/elementalsouls-hunt-auth-bypass/install","repository":"https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-auth-bypass"},"meta":{"agent_friendly":true,"api_version":"1.0","generated_at":"2026-09-05T16:55:04.620Z"}}