{"slug":"elementalsouls-hunt-csrf","source_name":"elementalsouls/hunt-csrf","name":"Elementalsouls/Hunt CSRF","description":"Hunting skill for csrf vulnerabilities. Built from 15 public bug bounty reports including modern variants — SameSite=Lax sibling-subdomain bypass (Argo CD CVE-2024-22424), GraphQL mutations-via-GET (GitLab $3,370), framework-wide CSRF middleware disabled (Stripe Dashboard $5,000), path-traversal CSRF-token bypass (GitHub Enterprise CVE-2022-23732 $10k), Origin-omission bypass (TikTok $2,500), OAuth-state null-byte (Streamlabs), WebSocket CSRF / CSWSH (Coda), default-SameSite email-change → ATO (","version":1,"lift":{"pass_rate_delta_pts":22.73,"pass_rate_pct":86.4,"total_cases":22,"passed_cases":19,"tokens_delta_pct":237.1,"turns_delta_pct":0,"verdict":"mixed","benchmark_model":"gemini-3.6-flash","grading_method":"judged","completed_at":"2026-08-09T13:28:06.371722+00:00"},"skill_score":null,"benchmark_models":[{"model":"gemini-3.6-flash","headline":true,"delta_pts":22.73,"with_pass_pct":86.4,"without_pass_pct":63.6,"tokens_delta_pct":237.1,"turns_delta_pct":0,"total_cases":22,"cases_aggregated":22,"verdict":"mixed","never_hurt":false,"completed_at":"2026-08-09T13:28:06.371722+00:00","run_id":"c7eef53a-c5a4-4e12-9951-152e5ea825fd","version_number":1,"is_latest_version":true,"gate":null}],"trust":{"skill_safety":"passed","safety_status":"clean","intent_verdict":"safe","content_status":"clean","indexable":true},"license":"NOASSERTION","install_count":0,"manifest_hash":"7bec3d66c5056db8e1b44b2af105d1cb16e02ad873ddb04e7cdd1605f4fb6058","raw_url":"https://app.decimal.ai/s/elementalsouls-hunt-csrf/SKILL.md","scorecard_url":"https://app.decimal.ai/skills/elementalsouls-hunt-csrf"}