hunt-idor (Claude-BugHunter)
IDOR-hunting skill distilled from 26 public bug-bounty reports.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for hunt-idor (Claude-BugHunter), derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
A focused offensive skill for finding Insecure Direct Object Reference (IDOR) vulnerabilities, built from 26 disclosed HackerOne/GitHub reports with 'crown jewel' target patterns. Surface: guides authenticated request tampering and object-id enumeration against live web targets.
Key features and capabilities
- Built from 26 real disclosed reports
- Crown-jewel target patterns
- Part of the Claude-BugHunter hunting suite
Use cases
- Hunt IDOR on an authorized target
- Enumerate object-reference access-control gaps