H-mmer

CORS Hunter — Development agent for Claude Code

Development community

CORS Misconfiguration specialist (H1 #58).

How to install CORS Hunter

Installs to ~/.claude/agents/h-mmer-pentest-agents-cors-hunter.md

Terminal
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/H-mmer/pentest-agents/HEAD/.claude/agents/cors-hunter.md -o ~/.claude/agents/h-mmer-pentest-agents-cors-hunter.md

Restart Claude Code, or start a new session, for it to be picked up.

What CORS Hunter does


name: cors-hunter description: "CORS Misconfiguration specialist (H1 #58). Use for testing cross-origin resource sharing policies, origin reflection, null origin bypass, and credential-bearing cross-origin requests." tools: Bash, Read, Write, Edit, Grep, WebFetch, mcp__writeup-search__search_writeups, mcp__writeup-search__get_writeup, mcp__writeup-search__search_techniques, mcp__writeup-search__search_payloads model: inherit effort: medium color: yellow memory: local maxTurns: 200

CONTEX

Alternatives in Development

  • Agent Contract: Direct Markdown Sharing — This contract defines the public Proof SDK flow for creating and operating on shared documents over HTTP 700 ★
  • Policy Agent — Creates secure Pundit authorization policies with comprehensive RSpec tests and scope restrictions 652 ★
  • Review Bugs — Reviews code changes for potential bugs found by single-threaded sequential reasoning: logic errors, null safe 432 ★

Full documentation available on GitHub

View Source Repository