Skill comparison
Use this as a shortlist, then open the skill detail page before adopting.
Decision summary
Strongest overall
hunt-cors
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Fastest prototype
hunt-cors
Best first install candidate based on install readiness and adoption.
Freshest repo
hunt-cors
Most recent maintenance signal among this shortlist.
| Signal | hunt-cors Hunt CORS Misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchored vs unescaped-dot vs prefix-only), pre-flight (OPTIONS) gating bypass, postMessage origin checks. High only when an attacker-controlled origin can perform a CREDENTIALED cross-origin read of sensitive data and you have proven it in a browser. Use when testing API endpoints, SPAs, or any app emitting Access-Control-* headers. |
|---|---|
| Quality | 83/100 Strong |
| Decision verdict | 94/100 Production-ready Use this as a leading candidate, then validate the README and install path in your own agent stack. |
| Adoption | 4.1K stars Verified outcomes are shown on each skill page |
| Freshness | Sep 2, 2026 |
| Use-case fit | |
| Workflow fit | |
| Platform hints | Claude Code, Browser agents |
| Warnings | No OpenAgentSkill engagement data yet |
| Best for |
Skill comparison
Use this as a shortlist, then open the skill detail page before adopting.
Decision summary
Strongest overall
hunt-cors
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Fastest prototype
hunt-cors
Best first install candidate based on install readiness and adoption.
Freshest repo
hunt-cors
Most recent maintenance signal among this shortlist.
| Signal | hunt-cors Hunt CORS Misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchored vs unescaped-dot vs prefix-only), pre-flight (OPTIONS) gating bypass, postMessage origin checks. High only when an attacker-controlled origin can perform a CREDENTIALED cross-origin read of sensitive data and you have proven it in a browser. Use when testing API endpoints, SPAs, or any app emitting Access-Control-* headers. |
|---|---|
| Quality | 83/100 Strong |
| Decision verdict | 94/100 Production-ready Use this as a leading candidate, then validate the README and install path in your own agent stack. |
| Adoption | 4.1K stars Verified outcomes are shown on each skill page |
| Freshness | Sep 2, 2026 |
| Use-case fit | |
| Workflow fit | |
| Platform hints | Claude Code, Browser agents |
| Warnings | No OpenAgentSkill engagement data yet |
| Best for |
| Browser automation workflows · Claude Code teams · teams that value GitHub adoption signals |
| Not ideal for | teams that need a vendor-supported SLA · high-compliance environments without internal security review |
| OpenAgentSkill engagement | 0 views 0 install copies |
| Install | $ npx skills add elementalsouls/Claude-BugHunter --skill hunt-cors |
| Browser automation workflows · Claude Code teams · teams that value GitHub adoption signals |
| Not ideal for | teams that need a vendor-supported SLA · high-compliance environments without internal security review |
| OpenAgentSkill engagement | 0 views 0 install copies |
| Install | $ npx skills add elementalsouls/Claude-BugHunter --skill hunt-cors |