mit einem Klick
csrf-hunter
Tests state-changing endpoints for Cross-Site Request Forgery by auditing for anti-CSRF tokens, SameSite cookie protection, method-swapping bypasses, Referer/Origin header enforcement, and token-to-session binding. Use when authenticated endpoints modify state (password change, transfer, delete, permission changes) and the request is not obviously API-fetch-only; when session cookies lack SameSite protection; or when the orchestrator's inventory surfaces POST/PUT/PATCH/DELETE endpoints without visible tokens. Produces findings with CWE-352 mapping, auto-submit HTML PoCs, and token/cookie remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.
Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.