CtrlK
BlogDocsLog inGet started
Tessl Logo

hunt-saml

Hunt SAML / SSO attacks. Patterns: XML Signature Wrapping (XSW) — modify Assertion while keeping Signature valid by relocating signed element, comment injection in NameID (admin@target.com<!--evil-->@attacker.com → some parsers see admin@target.com), signature stripping (remove Signature element entirely, server should reject but doesn't), key confusion (signed by attacker's IdP, accepted by SP), audience-restriction not validated, replay attack (same Assertion accepted twice within validity window). Tools: SAML Raider Burp extension, samlmagic, manual XML manipulation. Detection: any /saml endpoint, /Shibboleth.sso, /sso/saml/, Microsoft ADFS endpoints. Validate: account takeover via altered NameID, admin role injection via altered AttributeStatement. Use when hunting SSO flows, when SAML AssertionConsumerService is reachable, when chaining IdP-trust to SP-impersonation.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, token-efficient catalog of SAML attacks with copy-paste payloads and commands. Its weaknesses are the absence of explicit validation checkpoints for the destructive ATO workflows (capping workflow clarity) and a monolithic single-file structure with no local progressive disclosure.

Suggestions

Add explicit validation checkpoints to each attack workflow (e.g. 'Confirm ATO by checking the session user identity in a follow-up request') so destructive operations have verify-then-report feedback loops.

Split the XSW template variants, comment-injection parser-difference payloads, and NameID test lists into separate reference files under references/ and link to them one level deep, rather than inlining everything in SKILL.md.

Reorder so the core recon → attack → validate → triage sequence is one numbered workflow, making the multi-step process and its checkpoints explicit instead of spread across separate Attack sections.

DimensionReasoningScore

Conciseness

Efficient body that assumes Claude's competence—no basic XML/SAML primers—and most tokens earn their place; the comment-injection discrepancy explanation is slightly long but justified, keeping it just below a 5.

4 / 5

Actionability

Fully executable guidance: copy-paste base64 decode/re-encode commands ('base64 -w0 saml.xml'), concrete XML XSW and XXE payloads, a recon grep one-liner, and the exact SAML Raider Burp workflow steps covering the common cases.

5 / 5

Workflow Clarity

Attack steps are sequenced with a triage table, but this is a destructive/batch XML-manipulation skill (account takeover) lacking explicit validate-the-impact-checkpoints beyond the severity table; per the rubric cap, destructive skills without validation steps cannot exceed 3.

3 / 5

Progressive Disclosure

The body is a single ~113-line monolithic file with section headers but no bundle files; content that could live in separate references (e.g. the XSW payload catalog delegated to security-arsenal) is inlined, and external references are to other skills rather than to local one-level-deep files.

3 / 5

Total

15

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A dense, highly specific description that comprehensively enumerates SAML/SSO attack patterns, tools, detection endpoints, and explicit use-when triggers. It is borderline verbose but every clause is concrete rather than fluffy, and both the 'what' and 'when' are clearly answered.

DimensionReasoningScore

Specificity

Lists multiple concrete attack actions—'modify Assertion while keeping Signature valid by relocating signed element', 'comment injection in NameID', 'signature stripping', 'key confusion', 'audience-restriction not validated', 'replay attack'—with comprehensive coverage of the SAML attack surface.

5 / 5

Completeness

Explicitly answers both 'what' (attack patterns, tools, detection endpoints) and 'when' via the concrete 'Use when hunting SSO flows, when SAML AssertionConsumerService is reachable, when chaining IdP-trust to SP-impersonation' trigger clause.

5 / 5

Trigger Term Quality

Good keyword coverage including 'SAML', 'SSO', 'SAML Raider', 'samlmagic', '/saml endpoint', '/Shibboleth.sso', and 'Microsoft ADFS', plus natural 'Use when hunting SSO flows' phrasing; slightly jargon-heavy and missing a few plain-synonym terms, so just below 5.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (SAML/SSO attack hunting) with protocol-specific triggers like '/Shibboleth.sso' and 'ADFS endpoints', making conflict with other skills minimal.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.