Hunt Missing/Weak Rate Limiting — login brute force, OTP/2FA brute force (10^6 keyspace), password-reset-token brute, credential stuffing, username/email enumeration via error-string / status-code / timing differences, weak password policy, missing CAPTCHA (CAPTCHA token replay / single-use / concurrency-window bypass specifics → hunt-captcha-bypass), IP-based rate-limit bypass via X-Forwarded-For and friends, ReDoS. Distinguishes hard lockout vs soft IP-throttle vs CAPTCHA-injection vs silent shadow-throttling (avoids false-negative 'no rate limit' conclusions). Medium to Critical depending on what the brute reaches (OTP→ATO = Critical).
68
83%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Security
3 findings: 2 critical severity, 1 high severity. Installing this skill is not recommended: please review these findings carefully if you do intend to do so.
Detected a prompt injection in the skill instructions. The skill contains hidden or deceptive instructions that fall outside its stated purpose and attempt to override the agent’s safety guidelines or intended behavior.
This skill provides explicit, actionable instructions and automation (scripts, tooling flags, IP/header rotation techniques, full-keyspace brute procedures) for bypassing rate limits and brute-forcing OTPs/password-reset tokens and other credentials, directly enabling account takeover and large-scale abuse.
Detected high-risk code patterns in the skill content — including its prompts, tool definitions, and resources — such as data exfiltration, backdoors, remote code execution, credential theft, system compromise, supply chain attacks, and obfuscation techniques.
The document contains explicit, actionable and runnable attack scripts and commands (curl brute loops, a seeded "known-good" OTP probe, ffuf/hydra automation, and IP-header rotation) that enable automated OTP/reset-token brute-forcing, credential stuffing and rate-limit bypass — demonstrating intent to perform unauthorized access and a viable runtime mechanism.
The skill handles credentials insecurely by requiring the agent to include secret values verbatim in its generated output. This exposes credentials in the agent’s context and conversation history, creating a risk of data exfiltration.
The skill's example scripts and PoC commands require placing sensitive values (session cookies, OTP/reset tokens) directly into curl/ffuf headers and data (e.g. $SESSION_COOKIE, KNOWN_GOOD OTP, extracted reset tokens), which forces any agent that fills them to handle and output secrets verbatim.
58017df
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.