{"slug":"elementalsouls-hunt-clickjacking","source_name":"elementalsouls/hunt-clickjacking","name":"Elementalsouls/Hunt Clickjacking","description":"Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisible iframe and trick victims into clicking buttons they cannot see (UI redressing). Targets: login flows, money transfers, account settings, OAuth confirmation pages. Confirm by fetching the page, then PROVE it frames in a real browser and a sensitive state-changing action survives the cross-site context (SameSite cookies / framebusting JS can defeat it) — header-absence alone is ","version":1,"lift":{"pass_rate_delta_pts":13.64,"pass_rate_pct":86.4,"total_cases":22,"passed_cases":19,"tokens_delta_pct":15.8,"turns_delta_pct":0,"verdict":"mixed","benchmark_model":"gemini-3.6-flash","grading_method":"judged","completed_at":"2026-08-10T02:09:45.037521+00:00"},"skill_score":null,"benchmark_models":[{"model":"gemini-3.6-flash","headline":true,"delta_pts":13.64,"with_pass_pct":86.4,"without_pass_pct":72.7,"tokens_delta_pct":15.8,"turns_delta_pct":0,"total_cases":22,"cases_aggregated":22,"verdict":"mixed","never_hurt":true,"completed_at":"2026-08-10T02:09:45.037521+00:00","run_id":"767a834e-956e-43f0-8aab-a810b9dc84af","version_number":1,"is_latest_version":true,"gate":null}],"trust":{"skill_safety":"passed","safety_status":"clean","intent_verdict":"safe","content_status":"clean","indexable":true},"license":"NOASSERTION","install_count":0,"manifest_hash":"766fb80c0e30ea311cc62e436f0a0e6c916dce9e6f0262bc97cdcebd7674c000","raw_url":"https://app.decimal.ai/s/elementalsouls-hunt-clickjacking/SKILL.md","scorecard_url":"https://app.decimal.ai/skills/elementalsouls-hunt-clickjacking"}