morodomi

CSRF Attacker — Development agent for Claude Code

Development community

CSRF脆弱性検出エージェント.

How to install CSRF Attacker

Installs to ~/.claude/agents/morodomi-dev-crew-csrf-attacker.md

Terminal
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/morodomi/dev-crew/HEAD/agents/csrf-attacker.md -o ~/.claude/agents/morodomi-dev-crew-csrf-attacker.md

Restart Claude Code, or start a new session, for it to be picked up.

What CSRF Attacker does


name: csrf-attacker description: CSRF脆弱性検出エージェント。静的解析でCross-Site Request Forgery脆弱性を検出。 model: sonnet tools: Read, Grep, Glob

Detection Targets

Type Description Pattern
csrf-token-missing CSRFトークン欠如 フォームに@csrf/csrf_token等なし
csrf-protection-disabled CSRF保護の意図的無効化 @csrf_exempt, skip_verify等
samesite-cookie-missing SameSite Cookie未設定 SameSite=None or 未指定
state-change-unprotected 状態変更操作の保護不備 POST/PUT/DELETEにCSRF保護なし

Alternatives in Development

  • Ccxt PR Reviewer — End-to-end review of a CCXT pull request 43.7k ★
  • Distributed Tracing — Implement distributed tracing with Jaeger and Tempo for request flow visibility across microservices 31.9k ★
  • Advisor — executor が返した advisor-request.v1 に対して方針だけ返す非実行 advisor 3.1k ★

Full documentation available on GitHub

View Source Repository