CORS Hunter — Development agent for Claude Code
CORS Misconfiguration specialist (H1 #58).
How to install CORS Hunter
Installs to ~/.claude/agents/h-mmer-pentest-agents-cors-hunter.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/H-mmer/pentest-agents/HEAD/.claude/agents/cors-hunter.md -o ~/.claude/agents/h-mmer-pentest-agents-cors-hunter.md Restart Claude Code, or start a new session, for it to be picked up.
What CORS Hunter does
name: cors-hunter description: "CORS Misconfiguration specialist (H1 #58). Use for testing cross-origin resource sharing policies, origin reflection, null origin bypass, and credential-bearing cross-origin requests." tools: Bash, Read, Write, Edit, Grep, WebFetch, mcp__writeup-search__search_writeups, mcp__writeup-search__get_writeup, mcp__writeup-search__search_techniques, mcp__writeup-search__search_payloads model: inherit effort: medium color: yellow memory: local maxTurns: 200
CONTEX
Alternatives in Development
- Agent Contract: Direct Markdown Sharing — This contract defines the public Proof SDK flow for creating and operating on shared documents over HTTP 700 ★
- Policy Agent — Creates secure Pundit authorization policies with comprehensive RSpec tests and scope restrictions 652 ★
- Review Bugs — Reviews code changes for potential bugs found by single-threaded sequential reasoning: logic errors, null safe 432 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Deep Review Guard Bypass
Traces guard functions (permission, capacity, rate-limit, validation) to find any code path that reaches a pro
CSRF Hunter
CSRF specialist (H1 #57). Use for testing state-changing actions without proper token validation, SameSite coo
iOS Semgrep Hunter
Runs Semgrep over an unpacked IPA bundle (plists, entitlements, embedded JS and HTML, bundled source) and file
Access Control Hunter
Active IDOR / BOLA / BFLA / mass-assignment hunter for an ingested program. Consumes webvuln-surface injection
PRD Edge Case Analyzer
Use this agent when the user has completed or is finalizing a Product Requirement Document (PRD) and wants a t
Correlator
Finding correlation engine. Use AFTER multiple agents have reported findings to discover attack chains. Combin
Related Skills
CORS
Scan an endpoint for CORS misconfiguration — arbitrary-origin reflection, null-origin trust, credential exposu
Hackz Huntkit
Offensive-security playbooks for AI coding agents — IDOR, 403 bypass, CORS, finding validation and dupe-checki
Claude Sandbox
Run Claude Code in a hardened WSL2 distro on Windows. Rootless Podman boundary, tiered policies, credential gu