hunt-clickjacking

SKILLFlujo de trabajocomunidad
v0.0.0elementalsoulsMITActualizado hace 5 dFuente →

Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisible iframe and trick victims into clicking buttons they cannot see (UI redressing). Targets: login flows, money transfers, account settings, OAuth confirmation pages. Confirm by fetch

Community-submitted skill. Not yet reviewed by the Forge team. Full prompt content may not be available.Request review →
4kEstrellas del repo
1Clientes
1Formatos
hace 5 dÚltima actualización
Skill
Autorelementalsouls
Versión0.0.0
LicenciaMIT
CategoríaFlujo de trabajo
Formatosskill.md
PromptAbrir (ver la pestaña Prompt)
Compatibilidad
Claude✓ Compatible
Cursor
Copilot
ChatGPT
Gemini
Acerca de

Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisible iframe and trick victims into clicking buttons they cannot see (UI redressing). Targets: login flows, money transfers, account settings, OAuth confirmation pages. Confirm by fetching the page, then PROVE it frames in a real browser and a sensitive state-changing action survives

Palabras clave
skillclaude