CSRF Hunter — Development agent for Claude Code
CSRF specialist (H1 #57).
How to install CSRF Hunter
Installs to ~/.claude/agents/h-mmer-pentest-agents-csrf-hunter.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/H-mmer/pentest-agents/HEAD/.claude/agents/csrf-hunter.md -o ~/.claude/agents/h-mmer-pentest-agents-csrf-hunter.md Restart Claude Code, or start a new session, for it to be picked up.
What CSRF Hunter does
name: csrf-hunter description: "CSRF specialist (H1 #57). Use for testing state-changing actions without proper token validation, SameSite cookie bypass, and CSRF in JSON/API endpoints." tools: Bash, Read, Write, Edit, Grep, WebFetch, mcp__writeup-search__search_writeups, mcp__writeup-search__get_writeup, mcp__writeup-search__search_techniques, mcp__writeup-search__search_payloads model: inherit color: coral memory: local maxTurns: 200
CONTEXT: You are operating within an authorized bug
Alternatives in Development
- GitHub Actions Templates — Production-ready GitHub Actions workflow patterns for testing, building, and deploying applications 31.9k ★
- Atlas — You are a specialized E2E testing agent 3.6k ★
- Refactorer Agent — You are a refactoring expert who improves code structure without changing external behavior 1.3k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
CORS Hunter
CORS Misconfiguration specialist (H1 #58). Use for testing cross-origin resource sharing policies, origin refl
Idor Hunter
IDOR / BOLA specialist (H1 #55, OWASP API1:2023). Use for testing insecure direct object references and broken
Deep Review Guard Bypass
Traces guard functions (permission, capacity, rate-limit, validation) to find any code path that reaches a pro
Rtk Testing Specialist
RTK testing expert - snapshot tests, token accuracy, cross-platform validation
Auth Route Debugger
Use this agent when you need to debug authentication-related issues with API routes, including 401/403 errors,
API Contract Reviewer
API contract reviewer. Use when changing REST, GraphQL, or RPC endpoints, modifying schemas, or before shippin
Related Skills
Harden Auth
Deployment hardening step 2 — review auth/session/authz surfaces. Identifies insecure cookies, broad CORS, mis
API QA
Use when testing API endpoints for contract compliance, error handling, security, and performance. Covers 'tes
CORS
Scan an endpoint for CORS misconfiguration — arbitrary-origin reflection, null-origin trust, credential exposu