Skip to main content
تشغيل أي مهارة في Manus
بنقرة واحدة

csrf-hunter

النجوم١٥
التفرعات٧
آخر تحديث٢٨ يونيو ٢٠٢٦ في ١٦:٤٦

Tests state-changing endpoints for Cross-Site Request Forgery by auditing for anti-CSRF tokens, SameSite cookie protection, method-swapping bypasses, Referer/Origin header enforcement, and token-to-session binding. Use when authenticated endpoints modify state (password change, transfer, delete, permission changes) and the request is not obviously API-fetch-only; when session cookies lack SameSite protection; or when the orchestrator's inventory surfaces POST/PUT/PATCH/DELETE endpoints without visible tokens. Produces findings with CWE-352 mapping, auto-submit HTML PoCs, and token/cookie remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.

التثبيت

التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.

SKILL.md
readonly