★ ★ ★LIVE51 SPECIALIZED SKILLS ACROSS 8 ATTACK DOMAINS · BUGGY AI·VIEW SKILLS →★ ★ ★
BUGGY
buggy.hunt("https://target.com")→ [sqli] signal detectedclaude.triage(finding="blind-sqli")→ [7-gate] passed (7/7)recon.subdomains("target.com")→ [142] active assetsauth.audit_jwt(token="ey...")→ [none-alg] bypass foundbuggy.generate_report(cvss=9.8)→ [hackerone] markdown readyapi.probe_graphql("api.target.com/v1")→ [introspection] enabledm365.enum_users("target.com")→ [pw-spray] safe modemobile.decompile_apk("app.apk")→ [hardcoded-key] leakedbuggy.hunt("https://target.com")→ [sqli] signal detectedclaude.triage(finding="blind-sqli")→ [7-gate] passed (7/7)recon.subdomains("target.com")→ [142] active assetsauth.audit_jwt(token="ey...")→ [none-alg] bypass foundbuggy.generate_report(cvss=9.8)→ [hackerone] markdown readyapi.probe_graphql("api.target.com/v1")→ [introspection] enabledm365.enum_users("target.com")→ [pw-spray] safe modemobile.decompile_apk("app.apk")→ [hardcoded-key] leakedbuggy.hunt("https://target.com")→ [sqli] signal detectedclaude.triage(finding="blind-sqli")→ [7-gate] passed (7/7)recon.subdomains("target.com")→ [142] active assetsauth.audit_jwt(token="ey...")→ [none-alg] bypass foundbuggy.generate_report(cvss=9.8)→ [hackerone] markdown readyapi.probe_graphql("api.target.com/v1")→ [introspection] enabledm365.enum_users("target.com")→ [pw-spray] safe modemobile.decompile_apk("app.apk")→ [hardcoded-key] leaked
SKILLS/AUTH
> 5 SKILLS ACTIVE

Auth & Identity SECURITY DOMAIN

OAuth 2.0 flows, JWT attacks, ATO chains, SAML bypasses, and MFA bypass techniques drawn from 19–40 disclosed reports each.

5 SKILLS IN DOMAIN
🔐 CATEGORY
← All 8 Domains
/hunt-oauth
Auth & Identity
OAuth HunterOAuth 2.0 and OIDC vulnerabilities — CSRF on redirect_uri, state fixation, code injection, token leakage,...
claude "/hunt-oauth https://target.com" → trigger: auto-loaded
Both ✓19 reports
/hunt-ato
Auth & Identity
ATO HunterAccount takeover chains — password reset poisoning, username enumeration, token predictability, and sessi...
claude "/hunt-ato https://target.com" → trigger: auto-loaded
/hunt-auth-bypass
Auth & Identity
Auth Bypass HunterAuthentication bypass — JWT alg=none, weak HMAC secrets, path traversal in auth middleware, and HTTP verb...
claude "/hunt-auth-bypass https://target.com" → trigger: auto-loaded
/hunt-mfa-bypass
Auth & Identity
MFA Bypass HunterMulti-factor authentication bypass — code reuse, race conditions on OTP validation, backup code enumerati...
claude "/hunt-mfa-bypass https://target.com" → trigger: auto-loaded
/hunt-saml
Auth & Identity
SAML HunterSAML SSO vulnerabilities — signature wrapping, XML comment injection, NameID manipulation, and SP-initiat...
claude "/hunt-saml https://target.com" → trigger: auto-loaded