CSRF Attacker — Development agent for Claude Code
CSRF脆弱性検出エージェント.
How to install CSRF Attacker
Installs to ~/.claude/agents/morodomi-dev-crew-csrf-attacker.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/morodomi/dev-crew/HEAD/agents/csrf-attacker.md -o ~/.claude/agents/morodomi-dev-crew-csrf-attacker.md Restart Claude Code, or start a new session, for it to be picked up.
What CSRF Attacker does
name: csrf-attacker description: CSRF脆弱性検出エージェント。静的解析でCross-Site Request Forgery脆弱性を検出。 model: sonnet tools: Read, Grep, Glob
Detection Targets
| Type | Description | Pattern |
|---|---|---|
| csrf-token-missing | CSRFトークン欠如 | フォームに@csrf/csrf_token等なし |
| csrf-protection-disabled | CSRF保護の意図的無効化 | @csrf_exempt, skip_verify等 |
| samesite-cookie-missing | SameSite Cookie未設定 | SameSite=None or 未指定 |
| state-change-unprotected | 状態変更操作の保護不備 | POST/PUT/DELETEにCSRF保護なし |
Alternatives in Development
- Ccxt PR Reviewer — End-to-end review of a CCXT pull request 43.7k ★
- Distributed Tracing — Implement distributed tracing with Jaeger and Tempo for request flow visibility across microservices 31.9k ★
- Advisor — executor が返した advisor-request.v1 に対して方針だけ返す非実行 advisor 3.1k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
CSRF Hunter
CSRF specialist (H1 #57). Use for testing state-changing actions without proper token validation, SameSite coo
Dynamic Verifier
静的解析結果を動的に検証するエージェント。SQLi/XSS/Auth/CSRF/SSRF/File検証対応。
Attacker
ローカル環境のターゲットアプリを静的解析し、セキュリティ脆弱性を1件特定して報告する。コード上の指摘のみを行い、実行可能な攻撃スクリプトは生成しない。
Attack Surface
Stage 3 of Vulpine. Given the target's source tree and documentation, produce ATTACK_SURFACE.md — an enumerate
Enumeration Oracle Hunter
Use this agent to find side-channel and response-shape oracles that let an attacker enumerate names, existence
Auth Attacker
認証・認可脆弱性検出エージェント。静的解析でBroken Auth/Access Control脆弱性を検出。
Related Skills
Argue
Run an adversarial attacker/adjudicator discussion against an idea, work item, or decision.
Devil Mode
Parallel adversarial sweep — fires prompt-injection-hunter + supply-chain-auditor + secret-hunter + backdoor-h
Audit Security
Security audit (OWASP Top 10, PHP-specific vulnerabilities). Analyzes input validation, injection, authenticat