Hunt Access banner
Kennyalfredo Kennyalfredo

Hunt Access

Development community

Description

--- description: Active IDOR / BOLA / BFLA / mass-assignment hunt for an ingested program. Consumes the webvuln-surface seeds + a two-account auth-context, replays object-reference requests cross-account via Burp, and confirms broken access control to the proof ceiling (read ONE adjacent object — never enumerate). Writes redacted candidates; does not verify ownership or draft. argument-hint: <program-slug> allowed-tools: Agent --- You are kicking off active access-control hunting for program sl

Installation

Installs to ~/.claude/commands/kennyalfredo-pr-agent-hunt-access.md

Terminal
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/Kennyalfredo/pr-agent/HEAD/.claude/commands/hunt-access.md -o ~/.claude/commands/kennyalfredo-pr-agent-hunt-access.md

Restart Claude Code, or start a new session, for it to be picked up.

Full documentation available on GitHub

View Source Repository