Laporan audit skill

hunt-auth-bypass Laporan audit.

Hunting skill for auth bypass vulnerabilities. Built from 12 public bug bounty reports across SAML XSW / parser-differential (GitHub Enterprise CVE-2025-25291/25292), SAML signature stripping (Uber, Rocket.Chat, samlify CVE-2025-47949), SAML domain enforcement bypass via control characters (HackerOne 2024), partner-portal cross-IdP assertion reuse (Slack), WordPress XMLRPC bypassing SSO (Uber), JWT alg-confusion HS256/RS256 (Jitsi), JWT signature-validation skip (Linktree, Newspack), and token-audience confusion (Argo CD CVE-2023-22482). For standalone JWT signature/crypto forging (alg:none, key confusion, kid/jku) see hunt-jwt-crypto; this skill covers JWT only inside SSO/SAML/token-trust bypass chains. SAML assertion-layer attacks (XSW, comment injection, signature stripping, XXE-in-assertion) are owned by hunt-saml; this skill owns the broader cross-protocol auth-bypass taxonomy. Use when hunting auth bypass — see the Legacy-Protocol Matrix for branded-UI vs legacy-endpoint patterns

Diblokir · BlokirPerlu ditinjauDihasilkan 11 Okt 2026Audit metadata heuristik
77
Audit
68
Kepercayaan
80
Kualitas
70
Keamanan
88
Maintain
92
Pasang

Trust Score OpenAgentSkill

68
Tinjauan manual

Trust Score OpenAgentSkill

The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.

Adopsi GitHub

Lulus

86

4.1K star GitHub

Aktivitas star/fork

Lulus

83

4.1K star dan 637 fork; aktivitas issue tidak tersedia dalam metadata saat ini

Pemeliharaan terbaru

Lulus

88

1 bulan sejak push

Kejelasan lisensi

Lulus

86

MIT

Kelengkapan README/SKILL.md

Lulus

86

Metadata memuat konteks penggunaan dan alur kerja yang cukup

Risiko dependensi/runtime

Gagal

38

command execution surface, credential or environment access

Ketersediaan pemasangan

Lulus

92

npx skills add elementalsouls/Claude-BugHunter --skill hunt-auth-bypass

Keamanan perintah pemasangan

Lulus

92

Jalur pemasangan paket atau runtime standar

Cakupan izin

Gagal

18

secrets or environment access, shell or command execution

Bukti repositori

Lulus

86

https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-auth-bypass

Status peninjauan

Info

66

Data tinjauan AI tersedia

Hasil terbukti Agent

Info

54

Belum ada data hasil Agent

Pemeriksaan

Tinjauan pemasangan dan adopsi

8 Lulus · 14 Perlu ditinjau

Jalur pemasangan

92

Lulus

npx skills add elementalsouls/Claude-BugHunter --skill hunt-auth-bypass

Repositori

88

Lulus

https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-auth-bypass

Lisensi

86

Lulus

MIT

Pemeliharaan

88

Lulus

1 bulan sejak push

Tinjauan AI

55

Periksa

The SKILL.md excerpt is truncated in the review, but the provided content is sufficient to assess the skill.

Kelengkapan README/SKILL.md

86

Lulus

Usable description available

Risiko dependensi

38

Perbaiki

command execution surface, credential or environment access

Keamanan perintah pemasangan

92

Lulus

Jalur pemasangan paket atau runtime standar

Cakupan izin

18

Perbaiki

secrets or environment access, shell or command execution

Aktivitas star/fork

83

Lulus

4.1K star dan 637 fork; aktivitas issue tidak tersedia dalam metadata saat ini

Adopsi

88

Lulus

4.1K star GitHub

Financial decision safety

58

Periksa

Research-only use: do not treat output as financial advice or execute a position without human approval.

Peringatan

  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • Financial research output is not financial advice; require human review before any live investment decision
  • The SKILL.md excerpt is truncated in the review, but the provided content is sufficient to assess the skill.
  • The skill references other skills (hunt-jwt-crypto, hunt-saml) that are not included in this submission; users may need to obtain those separately for full coverage.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution

Metode

This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.

Bandingkan opsi sekitar

Skill terkait untuk diaudit berikutnya