MR
Mayur Rathi
@sickn33
⭐ 47.3k GitHub stars

hunt-cache-poison

hunt-cache-poison is an code AI skill with a core value of Hunting skill for cache poison vulnerabilities. It helps developers solve real-world problems in the code domain, boosting efficiency, automating repetitive tasks, and optimizing workflows.

Hunting skill for cache poison vulnerabilities.

Last verified on: 2026-10-06

Quick Facts

Category code
Works With Claude
Source sickn33/antigravity-awesome-skills
Stars ⭐ 47.3k
Last Verified 2026-10-06
Risk Level Low
mkdir -p ./skills/hunt-cache-poison && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/hunt-cache-poison/SKILL.md -o ./skills/hunt-cache-poison/SKILL.md

Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).

Skill Content

> **⚠️ AUTHORIZED USE ONLY**

> This skill is for educational purposes or authorized security assessments only.

> You must have explicit, written permission from the system owner before using this tool.

> Misuse of this tool is illegal and strictly prohibited.


> **Mandatory confirmation gate**

> Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:

> 1. Ask the user to state the exact target URL, IP, account, or resource.

> 2. Ask the user to confirm written authorization and the permitted scope.

> 3. Show the exact command(s) and explain their expected effect.

> 4. Wait for explicit confirmation in the current conversation.

>

> Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.


Crown Jewel Targets


Cache poisoning is high-value because a single poisoned cache entry can affect thousands or millions of victims simultaneously — one request, mass exploitation. Payout scales with blast radius.


**Highest-value targets:**

- **CDN-served assets** (cdn.shopify.com, cloudfront distributions, Fastly/Akamai edges) — poisoning these affects every visitor globally

- **E-commerce platforms** with affiliate/referral flows (Shopify, WooCommerce storefronts) — session hijack or affiliate fraud potential

- **Gaming platforms with update servers** (rockstargames updates.* domains) — DoS on update delivery = widespread client breakage

- **Authentication endpoints** served through caches — leads to account takeover (the highest severity variant)

- **Asset CDNs** (JS/CSS delivery) — XSS payload delivery at scale

- **SaaS multi-tenant platforms** — one poisoned response bleeds into all tenants sharing a cache key


**Asset types that pay most:** CDN hostnames, subdomain-per-tenant patterns, update/download servers, login/account pages cached incorrectly, affiliate link shorteners.


---


Autonomous Testing Priority


**Two distinct attacks live under this skill — target the simpler one first.**


**Attack 1 — Password Reset Poisoning (Host header injection):**


The app uses the `Host` header to construct the password reset link in the email. Inject an attacker-controlled hostname; the victim's reset email contains a link to your server.


text
POST /forgot-password
Host: attacker.com
X-Forwarded-Host: attacker.com
X-Host: attacker.com

email=victim@target.com
Content-Type: application/x-www-form-urlencoded

Use a distinctive hostname you control or can identify in the response. **Proof:** the injected hostname appears in the response body (some apps reflect the generated reset link), or the action succeeds (2xx with a "reset email sent" message) after injection — confirming the poisoned link would be sent to the victim.


Try multiple host headers — apps vary in which one they trust (`X-Forwarded-Host` is most common, but `Host` itself also works when the proxy passes it through).


**Attack 2 — Web Cache Poisoning:**


Inject the attacker-controlled hostname into `X-Forwarded-Host` on a GET request for a cacheable page. If the hostname is reflected in the response body AND the response gets cached, subsequent visitors receive the poisoned response.


Check for cache signals in the response: `X-Cache: HIT`, `CF-Cache-Status: HIT`, `Age: <nonzero>`, or `Via: cloudfront/varnish/fastly`.


**Proof for both:** injected value reflected in response body, or action completed successfully despite the manipulated header.


---


Attack Surface Signals


**URL patterns to look for:**

- `cdn.`, `assets.`, `static.`, `updates.`, `downloads.` subdomains

- URL path structures with extensions that look static: `/path/to/page.css`, `/account.php/nonexistent.jpg`

- Affiliate/link shortener endpoints: `/link/`, `/go/`, `/ref/`, `/out/`

- Paths that mix dynamic content with cacheable-looking URLs


**Response headers that signal a cache:**

text
X-Cache: HIT / MISS
X-Cache-Status: HIT
CF-Cache-Status: HIT

🎯 Best For

  • Claude users
  • Software engineers
  • Development teams
  • Tech leads

💡 Use Cases

  • Code quality improvement
  • Best practice enforcement

📖 How to Use This Skill

  1. 1

    Install the Skill

    Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.

  2. 2

    Load into Your AI Assistant

    Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.

  3. 3

    Apply hunt-cache-poison to Your Work

    Open your project in the AI assistant and ask it to apply the skill. Start with a small module to verify the output quality.

  4. 4

    Review and Refine

    Review AI suggestions before committing. Run tests, check for regressions, and iterate on the skill output.

❓ Frequently Asked Questions

Is hunt-cache-poison compatible with Cursor and VS Code?

Yes — this skill works with any AI coding assistant including Cursor, VS Code with Copilot, and JetBrains IDEs.

Do I need specific dependencies for hunt-cache-poison?

Check the install command and Works With section. Most code skills only require the AI assistant and your codebase.

How do I install hunt-cache-poison?

Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/hunt-cache-poison/SKILL.md, ready to use.

Can I customize this skill for my team?

Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.

⚠️ Common Mistakes to Avoid

Skipping validation

Always test AI-generated code changes, even for simple refactors.

Missing dependency updates

Check if the skill requires updated dependencies or new packages.

🔗 Related Skills