{"skill":{"slug":"elementalsouls-hunt-captcha-bypass","name":"hunt-captcha-bypass","description":"Hunt CAPTCHA Bypass — 6 distinct patterns: (1) CAPTCHA field simply omitted from the request (server-side validation absent), (2) CAPTCHA token replayed from a solved challenge (no single-use enforcement), (3) CAPTCHA response accepted on a different endpoint than it was solved on (no binding to action/session), (4) static or predictable CAPTCHA values accepted (e.g. '0', 'null', empty string), (5) audio/accessibility CAPTCHA trivially solvable programmatically, (6) CAPTCHA only enforced after N failures (first N requests bypass it). Detection: intercept a successful form submission, remove the CAPTCHA field entirely, replay — if it still succeeds, server-side validation is absent. Medium severity standalone; High when it removes the only rate-limit gate protecting a login, registration, or payment endpoint.","repository":"https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-captcha-bypass"},"recommended_command":"npx skills add elementalsouls/Claude-BugHunter --skill hunt-captcha-bypass","install_targets":[{"id":"openagentskill-cli","label":"CLI","title":"OpenAgentSkill CLI","kind":"command","value":"npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.3.0/openagentskill-0.3.0.tgz add elementalsouls-hunt-captcha-bypass","description":"Resolve policy, run the source installer safely, and report a verified install receipt.","copyLabel":"Copy command"},{"id":"codex","label":"Codex","title":"Codex install prompt","kind":"agent-prompt","value":"Install the \"hunt-captcha-bypass\" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-captcha-bypass. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Hunt CAPTCHA Bypass — 6 distinct patterns: (1) CAPTCHA field simply omitted from the request (server-side validation absent), (2) CAPTCHA token replayed from a solved challenge (no single-use enforcement), (3) CAPTCHA response accepted on a different endpoint than it was solved on (no binding to action/session), (4) static or predictable CAPTCHA values accepted (e.g. '0', 'null', empty string), (5) audio/accessibility CAPTCHA trivially solvable programmatically, (6) CAPTCHA only enforced after N failures (first N requests bypass it). Detection: intercept a successful form submission, remove the CAPTCHA field entirely, replay — if it still succeeds, server-side validation is absent. Medium severity standalone; High when it removes the only rate-limit gate protecting a login, registration, or payment endpoint. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"elementalsouls-hunt-captcha-bypass\",\"task\":\"Install hunt-captcha-bypass\",\"agent\":\"codex\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.","description":"Give Codex a repo-aware install prompt when the skill is not available through a local CLI.","copyLabel":"Copy prompt"},{"id":"claude-code","label":"Claude Code","title":"Claude Code skill prompt","kind":"agent-prompt","value":"Add \"hunt-captcha-bypass\" as a Claude Code skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-captcha-bypass. Inspect the skill instructions, place the reusable skill files in the appropriate local skills location for this project, and report the activation steps. Skill purpose: Hunt CAPTCHA Bypass — 6 distinct patterns: (1) CAPTCHA field simply omitted from the request (server-side validation absent), (2) CAPTCHA token replayed from a solved challenge (no single-use enforcement), (3) CAPTCHA response accepted on a different endpoint than it was solved on (no binding to action/session), (4) static or predictable CAPTCHA values accepted (e.g. '0', 'null', empty string), (5) audio/accessibility CAPTCHA trivially solvable programmatically, (6) CAPTCHA only enforced after N failures (first N requests bypass it). Detection: intercept a successful form submission, remove the CAPTCHA field entirely, replay — if it still succeeds, server-side validation is absent. Medium severity standalone; High when it removes the only rate-limit gate protecting a login, registration, or payment endpoint. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"elementalsouls-hunt-captcha-bypass\",\"task\":\"Install hunt-captcha-bypass\",\"agent\":\"claude-code\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.","description":"Use this prompt to ask Claude Code to add the skill and explain the local activation steps.","copyLabel":"Copy prompt"},{"id":"cursor","label":"Cursor","title":"Cursor rule prompt","kind":"agent-prompt","value":"Turn \"hunt-captcha-bypass\" from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-captcha-bypass into a reusable Cursor project rule or agent instruction. Preserve the core workflow, adapt paths to this repo, and keep the rule scoped to tasks where it is relevant. Skill purpose: Hunt CAPTCHA Bypass — 6 distinct patterns: (1) CAPTCHA field simply omitted from the request (server-side validation absent), (2) CAPTCHA token replayed from a solved challenge (no single-use enforcement), (3) CAPTCHA response accepted on a different endpoint than it was solved on (no binding to action/session), (4) static or predictable CAPTCHA values accepted (e.g. '0', 'null', empty string), (5) audio/accessibility CAPTCHA trivially solvable programmatically, (6) CAPTCHA only enforced after N failures (first N requests bypass it). Detection: intercept a successful form submission, remove the CAPTCHA field entirely, replay — if it still succeeds, server-side validation is absent. Medium severity standalone; High when it removes the only rate-limit gate protecting a login, registration, or payment endpoint. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"elementalsouls-hunt-captcha-bypass\",\"task\":\"Install hunt-captcha-bypass\",\"agent\":\"cursor\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.","description":"Use this when installing as Cursor project rules or reusable agent instructions.","copyLabel":"Copy prompt"}],"install_receipt":{"endpoint":"https://www.openagentskill.com/api/agent/outcome","method":"POST","idempotency":"event_id is unique; retries update the same receipt","count_rule":"verified installs require install_used=true and outcome=success","example":{"event_id":"install_<unique-id>","skill_slug":"elementalsouls-hunt-captcha-bypass","task":"Install hunt-captcha-bypass","agent":"codex","outcome":"success","install_used":true}},"safety_gate":{"tier":"reviewed","label":"Reviewed with permission notes","badge":"REVIEWED","auto_install_policy":"review","auto_install_allowed":false,"human_review_required":true,"blocked":false,"recommended_action":"Require human approval before installing into a real workspace.","reasons":["High-risk permission hints: Secrets or environment access","58/100 agent safety score"]},"agent_prompt":"Install the \"hunt-captcha-bypass\" agent skill only after reviewing the OpenAgentSkill profile and source repository. Safety gate: Reviewed with permission notes (review). Start with https://www.openagentskill.com/skills/elementalsouls-hunt-captcha-bypass, inspect the trust and audit notes, then use the recommended install handoff: npx skills add elementalsouls/Claude-BugHunter --skill hunt-captcha-bypass. After installation, summarize changed files, required setup, and a minimal verification result before using the skill for real work. Report the verified result to https://www.openagentskill.com/api/agent/outcome using a unique event_id, skill_slug=elementalsouls-hunt-captcha-bypass, install_used=true, and outcome=success or failed.","safety_checklist":["Safety gate: Reviewed with permission notes. Policy: review.","Require human approval before installing into a real workspace.","Review the repository and license before running third-party code.","Prefer a sandbox or isolated project when testing a new skill.","Start with the recommended command, then inspect generated files before committing changes.","Do not execute external side effects, payments, account changes, or credentialed actions without explicit user approval."],"verification_steps":["Open the skill documentation or SKILL.md and identify required setup.","Run the smallest safe example for the target task.","Confirm outputs match the task before allowing broader agent use.","Record any missing credentials, policy risks, or manual approvals needed."],"do_not_auto_install_when":["The repository or license cannot be reviewed.","The skill requires broad credentials or production account access.","The task involves regulated, private, or high-impact data without user approval."],"urls":{"web":"https://www.openagentskill.com/skills/elementalsouls-hunt-captcha-bypass","api":"https://www.openagentskill.com/api/agent/skills/elementalsouls-hunt-captcha-bypass","install_api":"https://www.openagentskill.com/api/skills/elementalsouls-hunt-captcha-bypass/install","repository":"https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-captcha-bypass"},"meta":{"agent_friendly":true,"api_version":"1.0","generated_at":"2026-09-08T12:18:26.092Z"}}