Access Control Hunter
Description
--- name: access-control-hunter description: Active IDOR / BOLA / BFLA / mass-assignment hunter for an ingested program. Consumes webvuln-surface injection points + a two-account auth-context, replays object-reference requests cross-account via Burp, and confirms broken access control to the §4 proof ceiling (read ONE adjacent object, never enumerate). References the offensive-idor skill for technique. Writes redacted candidates to out/<slug>/webvuln/access/<ts>.json. Gated by §1. Does NOT verif
Installation
Installs to ~/.claude/agents/kennyalfredo-pr-agent-access-control-hunter.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/Kennyalfredo/pr-agent/HEAD/.claude/agents/access-control-hunter.md -o ~/.claude/agents/kennyalfredo-pr-agent-access-control-hunter.md Restart Claude Code, or start a new session, for it to be picked up.
Full documentation available on GitHub
View Source RepositoryRelated Agents
Django Build Resolver
Django/Python build, migration, and dependency error resolution specialist. Fixes pip/Poetry errors, migration
Development Openai Codex CLI
(55.8k ⭐) - Lightweight coding agent that runs in your terminal.
Development src/agents/ — 11 Agent Definitions
**Generated:** 2026-04-11
Development Cavecrew Builder
>
Development Cavecrew Investigator
>
Development Cavecrew Reviewer
>
Development Related Skills
Auto Update
Pull the latest ECC repo changes and reinstall the current managed targets.
Ecc Guide
Navigate ECC's current agents, skills, commands, hooks, install profiles, and docs from the live repository su
Epic Claim
Claim an epic issue, stamp coordination state, and sync local ownership.