OpenAgentSkill Registry Manifest Skill: hunt-cache-poison Slug: elementalsouls-hunt-cache-poison Category: security Description: Hunting skill for cache poison vulnerabilities. Built from 10 public bug bounty reports including X-Forwarded-Host poisoning, X-HTTP-Method-Override / GCS cache, reflected→stored XSS via cache, classic Omer-Gil Web Cache Deception, Cloudflare Cache Deception Armor bypass, session-token cache deception, Akamai hop-by-hop smuggling → server-side edge poisoning, and Kettle's 2024 path-normalization WCD against Cloudflare/Fastly/GCP. Host/X-Forwarded-Host injection that reaches app logic (reset-link poisoning, routing SSRF, OAuth issuer) is owned by hunt-host-header; this skill owns the case where the poisoned response is CACHED and served to other users. Use when hunting cache poisoning, Web Cache Deception, CDN-fronted apps. Agent fit: - Decision: 94/100 Production-ready - Primary fit: Coding agents - Role: Primary pick Supply profile: - Track: Coding and developer agents - Scenario: Coding agents - Applicable agents: Claude Code, CLI, Codex, Cursor - Maintenance: 3d since push - Risk: Needs review Trust: - Trust score: 68/100 Manual review - Audit: 80/100 Needs review Attribution: - Status: Registry indexed - Source: github candidate review - Creator: elementalsouls - Claim URL: https://www.openagentskill.com/skills/elementalsouls-hunt-cache-poison#claim-this-skill Install: npx skills add elementalsouls/Claude-BugHunter --skill hunt-cache-poison URLs: - Web: https://www.openagentskill.com/skills/elementalsouls-hunt-cache-poison - API: https://www.openagentskill.com/api/agent/skills/elementalsouls-hunt-cache-poison - Install API: https://www.openagentskill.com/api/skills/elementalsouls-hunt-cache-poison/install - Repository: https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-cache-poison