Idor Hunter — Development agent for Claude Code
IDOR / BOLA specialist (H1 #55, OWASP API1:2023).
How to install Idor Hunter
Installs to ~/.claude/agents/h-mmer-pentest-agents-idor-hunter.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/H-mmer/pentest-agents/HEAD/.claude/agents/idor-hunter.md -o ~/.claude/agents/h-mmer-pentest-agents-idor-hunter.md Restart Claude Code, or start a new session, for it to be picked up.
What Idor Hunter does
name: idor-hunter description: "IDOR / BOLA specialist (H1 #55, OWASP API1:2023). Use for testing insecure direct object references and broken object level authorization across web apps, APIs, GraphQL endpoints, multi-tenant SaaS, mobile, automotive/IoT, and AI inference servers." tools: Bash, Read, Write, Edit, Grep, WebFetch, mcp__writeup-search__search_writeups, mcp__writeup-search__get_writeup, mcp__writeup-search__search_techniques, mcp__writeup-search__search_payloads model: inherit co
Alternatives in Development
- SaaS Market Sizing — Complete TAM/SAM/SOM calculation for a B2B SaaS startup using bottom-up and top-down methodologies 31.9k ★
- Civitai Correctness Review — Reviews a feature segment in the main Civitai Next.js app (src/) for safety gaps — authorization scoping, mone 7.2k ★
- Recon Ranker — Attack surface ranking agent 4.5k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Access Control Hunter
Active IDOR / BOLA / BFLA / mass-assignment hunter for an ingested program. Consumes webvuln-surface injection
Penetration Tester
Use this agent for AUTHORIZED penetration testing of your own applications on local or staging environments on
Network Backend Auditor
Audits the mobile app's network layer and the backend API surface it talks to, including TLS config, BOLA/IDOR
SaaS Builder
Builds multi-tenant SaaS products on Next.js, Supabase and Stripe with auth, roles, billing, an admin panel an
Dotnet Senior Developer
.NET/C# backend/web engineer. Invoke for Clean Architecture, EF Core, FluentValidation, multi-tenant, GraphQL,
API Lite
Use when designing, reviewing, or implementing REST or GraphQL APIs - endpoints, contracts, versioning, or doc
Related Skills
API Security
API security audit (OWASP API Security Top 10 2023): BOLA/IDOR, broken authentication, broken object-property-
Hunt Access
Active IDOR / BOLA / BFLA / mass-assignment hunt for an ingested program. Consumes the webvuln-surface seeds +
Zp Corpus
Search 138,400 shipped public security write-ups by title, class, CVE or program, then fetch the URL to read o