# Hunt Csrf (agent skill)

> Hunt Csrf is an agent skill (a SKILL.md file) from elementalsouls/Claude-BugHunter. Hunting skill for csrf vulnerabilities. Built from 15 public bug bounty reports including modern variants — SameSite=Lax sibling-subdomain bypass (Argo CD CVE-2024-22424), GraphQL mutations-via-GET. It works with Claude Code, Codex and OpenCode and has 4,784 GitHub stars across a repository of 4 listed skills.

Hunting skill for csrf vulnerabilities. Built from 15 public bug bounty reports including modern variants — SameSite=Lax sibling-subdomain bypass (Argo CD CVE-2024-22424), GraphQL mutations-via-GET (GitLab $3,370), framework-wide CSRF middleware disabled (Stripe Dashboard $5,000), path-traversal CSRF-token bypass (GitHub Enterprise CVE-2022-23732 $10k), Origin-omission bypass (TikTok $2,500), OAuth-state null-byte (Streamlabs), WebSocket CSRF / CSWSH (Coda), default-SameSite email-change → ATO…

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/elementalsouls/Claude-BugHunter |
| Skill path | skills/hunt-csrf/SKILL.md |
| Skill name | hunt-csrf |
| GitHub stars | 4,784 |
| Installs on skills.sh | not listed |
| License | MIT |
| Skills in repo | 4 |
| Plugin marketplace | elementalsouls |
| Official | no |
| Works with | Claude Code, Codex, OpenCode |
| Category | Security |
| Last commit | Oct 6, 2026 |

## When it triggers

- Use when hunting modern CSRF — heavy emphasis on chain-to-ATO patterns.

## Add this skill

### Claude Code

```sh
/plugin marketplace add elementalsouls/Claude-BugHunter
/plugin install claude-bughunter@elementalsouls
```

In the Claude apps, zip the skill folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

### ChatGPT / Codex

```sh
git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git
cp -r Claude-BugHunter/skills/hunt-csrf .agents/skills/hunt-csrf   # repo; ~/.agents/skills for all projects
```

### Cursor

```sh
git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git
cp -r Claude-BugHunter/skills/hunt-csrf .cursor/skills/hunt-csrf   # project; ~/.cursor/skills for all projects
```

Sources (checked 2026-10-07): https://code.claude.com/docs/en/skills, https://support.claude.com/en/articles/12512180-using-skills-in-claude, https://learn.chatgpt.com/docs/build-skills, https://cursor.com/docs/context/skills

---

Canonical page: https://appsgit.com/skills/elementalsouls-hunt-csrf
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
