vigilantshield/Claude-HunterKit

The largest open-source offensive security skill library , 140 skills for web, API, AI, network. One command to hunt anything

5Stars on the repository
59Mods indexed here, across every type
1mo agoLast push, which is what freshness is scored on
noneNo LICENSE: all rights reserved, so bodies are not copied

vigilantshield/Claude-HunterKit

Skill Claude CodeCodex

API rate limiting and resource exhaustion testing skill. Covers rate limit bypass, resource exhaustion, pagination abuse, batch endpoint abuse, and denial-of-service via API resource consumption. Use when testing API rate limiting and resource controls.

not rated 5 1mo ago A 50 tokens

vigilantshield/Claude-HunterKit

Skill Claude CodeCodex

API cost/resource exhaustion: pagination abuse, expensive endpoint DoS, async job flooding, nested object expansion, and size limit bypass. Use when testing API resource limits.

not rated 5 1mo ago A 39 tokens

vigilantshield/Claude-HunterKit

Skill Claude CodeCodex

Distributed API race conditions: HTTP/2 single-packet attack, cross-endpoint TOCTOU, parallel write contention, rate-limit race bypass, and multi-step workflow races across microservices.

not rated 5 1mo ago A 46 tokens

api-26-supply-chain

52

vigilantshield/Claude-HunterKit

Skill Claude CodeCodex

API supply chain security testing skill. Covers dependency confusion, package hijacking, CI/CD pipeline attacks, third-party API trust, and upstream dependency vulnerability assessment. Use when evaluating API supply chain security.

not rated 5 1mo ago A 46 tokens

api-27-versioning

53

vigilantshield/Claude-HunterKit

Skill Claude CodeCodex

API versioning abuse: outdated version endpoint discovery, version diff analysis for weaker security controls, deprecated endpoint access, and authorization bypass via older API versions.

not rated 5 1mo ago A 36 tokens

vigilantshield/Claude-HunterKit

Skill Claude CodeCodex

Stateful API fuzzing: sequence-dependent endpoint testing, multi-step workflow fuzzing, state machine violation, and resource lifecycle manipulation. Use when testing complex API workflows.

not rated 5 1mo ago A 42 tokens

api-29-jwt

55

vigilantshield/Claude-HunterKit

Skill Claude CodeCodex

JWT attack methodology for penetration testers. Covers algorithm confusion (alg:none, RS256→HS256), weak HMAC secret brute force, kid parameter injection (SQLi, path traversal), jku/x5u/jwk header injection, JWKS cache poisoning, JWS/JWE confusion, timing attacks, and mobile JWT storage extraction. Use when testing…

not rated 5 1mo ago A 98 tokens

api-30-oauth

56

vigilantshield/Claude-HunterKit

Skill Claude CodeCodex

OAuth 2.0 attack checklist: authorization code interception, redirecturi bypass, CSRF on OAuth flow, state parameter abuse, open redirector chaining, token leakage via Referer, PKCE bypass, and scope escalation. Use when testing OAuth implementations in web apps or bug bounty.

not rated 5 1mo ago C 63 tokens

api-31-idor

57

vigilantshield/Claude-HunterKit

Skill Claude CodeCodex

IDOR (Insecure Direct Object Reference) testing checklist: object ID enumeration, horizontal/vertical privilege escalation, GUID predictability, indirect references via hashes, chained IDOR, and API endpoint IDOR. Use for web app pentests and bug bounty IDOR discovery.

not rated 5 1mo ago A 60 tokens

api-32-graphql

58

vigilantshield/Claude-HunterKit

Skill Claude CodeCodex

GraphQL security testing checklist: introspection abuse, batching attacks, query depth/complexity DoS, field suggestion enumeration, IDOR via GraphQL, injection through arguments, authorization bypass. Use when assessing GraphQL endpoints in web app tests or bug bounty.

not rated 5 1mo ago A 58 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: