Skip to main content
Jeden Skill in Manus ausführen
mit einem Klick

csrf-hunter

Sterne15
Forks7
Aktualisiert28. Juni 2026 um 16:46

Tests state-changing endpoints for Cross-Site Request Forgery by auditing for anti-CSRF tokens, SameSite cookie protection, method-swapping bypasses, Referer/Origin header enforcement, and token-to-session binding. Use when authenticated endpoints modify state (password change, transfer, delete, permission changes) and the request is not obviously API-fetch-only; when session cookies lack SameSite protection; or when the orchestrator's inventory surfaces POST/PUT/PATCH/DELETE endpoints without visible tokens. Produces findings with CWE-352 mapping, auto-submit HTML PoCs, and token/cookie remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.

Installation

Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.

SKILL.md
readonly