OpenAgentSkill Registry Manifest Skill: hunt-brute-force Slug: elementalsouls-hunt-brute-force Category: research Description: Hunt Missing/Weak Rate Limiting — login brute force, OTP/2FA brute force (10^6 keyspace), password-reset-token brute, credential stuffing, username/email enumeration via error-string / status-code / timing differences, weak password policy, missing CAPTCHA (CAPTCHA token replay / single-use / concurrency-window bypass specifics → hunt-captcha-bypass), IP-based rate-limit bypass via X-Forwarded-For and friends, ReDoS. Distinguishes hard lockout vs soft IP-throttle vs CAPTCHA-injection vs silent shadow-throttling (avoids false-negative 'no rate limit' conclusions). Medium to Critical depending on what the brute reaches (OTP→ATO = Critical). Agent fit: - Decision: 94/100 Production-ready - Primary fit: Research agents - Role: Primary pick Supply profile: - Track: Research and knowledge work - Scenario: Research agents - Applicable agents: Claude Code, CLI, Codex, Cursor - Maintenance: 4d since push - Risk: Needs review Trust: - Trust score: 73/100 Strong shortlist - Audit: 81/100 Needs review Attribution: - Status: Registry indexed - Source: github candidate review - Creator: elementalsouls - Claim URL: https://www.openagentskill.com/skills/elementalsouls-hunt-brute-force#claim-this-skill Install: npx skills add elementalsouls/Claude-BugHunter --skill hunt-brute-force URLs: - Web: https://www.openagentskill.com/skills/elementalsouls-hunt-brute-force - API: https://www.openagentskill.com/api/agent/skills/elementalsouls-hunt-brute-force - Install API: https://www.openagentskill.com/api/skills/elementalsouls-hunt-brute-force/install - Repository: https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-brute-force