Skip to main content
Run any Skill in Manus
with one click

clickjacking-hunter

Stars15
Forks7
UpdatedJune 28, 2026 at 16:46

Tests sensitive state-changing pages for clickjacking / UI-redress weaknesses by auditing frame-protection headers, cookie attributes, and pre-fillable URL parameters. Use when a web app has destructive or account-modifying actions (password change, transfer, delete) that complete with a single click; when X-Frame-Options / CSP frame-ancestors are missing or permissive; or when the orchestrator needs to confirm whether a finding can be exploited without a secondary confirmation. Produces findings with CWE-1021 mapping, a local framing PoC, and developer-facing header/cookie remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
2 files
SKILL.md
readonly