MR
Mayur Rathi
@sickn33
⭐ 47.3k GitHub stars

hunt-forgot-password

hunt-forgot-password is an code AI skill with a core value of Hunt Forgot Password / Account Recovery Authentication Flaws. It helps developers solve real-world problems in the code domain, boosting efficiency, automating repetitive tasks, and optimizing workflows.

Hunt Forgot Password / Account Recovery Authentication Flaws

Last verified on: 2026-10-06

Quick Facts

Category code
Works With Claude
Source sickn33/antigravity-awesome-skills
Stars ⭐ 47.3k
Last Verified 2026-10-06
Risk Level High
mkdir -p ./skills/hunt-forgot-password && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/hunt-forgot-password/SKILL.md -o ./skills/hunt-forgot-password/SKILL.md

Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).

Skill Content

> **⚠️ AUTHORIZED USE ONLY**

> This skill is for educational purposes or authorized security assessments only.

> You must have explicit, written permission from the system owner before using this tool.

> Misuse of this tool is illegal and strictly prohibited.


> **Mandatory confirmation gate**

> Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:

> 1. Ask the user to state the exact target URL, IP, account, or resource.

> 2. Ask the user to confirm written authorization and the permitted scope.

> 3. Show the exact command(s) and explain their expected effect.

> 4. Wait for explicit confirmation in the current conversation.

>

> Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.


Autonomous Testing Priority


**Start with username enumeration — it's the fastest win and gates the rest.**


**Pattern 1 — Username enumeration (response difference for valid vs invalid email):**

1. POST to the forgot-password endpoint with a clearly invalid email (e.g. `nonexistent@fakedomain12345.com`) — record the response body, status code, and length

2. POST with an email you know exists (or try common patterns like `admin@target.com`, `test@target.com`, `user@target.com`)

3. Compare responses: different message ("Email sent" vs "Email not found"), different HTTP status, or meaningfully different body length = username enumeration confirmed

4. Proof: enumeration is confirmed when the two responses differ measurably (baseline vs probe) in message text, status code, or body length


**Pattern 2 — Reset token exposed in the API response:**

Some APIs return the reset token directly in the response body (instead of only emailing it). POST to the forgot-password endpoint and look for a token, link, or code in the JSON/HTML response. If a token appears that lets you reset the password, that's an immediate account-takeover vector.


**Pattern 3 — Reset token replay (reuse after use):**

1. Complete a full password reset cycle: request token → use it to reset password

2. Immediately try submitting the same token again to the reset-password endpoint

3. If the second submission returns 200 or "success" → token not invalidated after use


**Pattern 4 — No rate limit on reset requests:**

Submit the forgot-password endpoint 10-20 times rapidly with the same email. If all succeed without a 429, lockout, or CAPTCHA → no rate limit (enumeration + token flooding is possible).


**Content-type:** Forgot-password endpoints are often JSON-based REST APIs. Use `application/x-www-form-urlencoded` only if the endpoint is a traditional HTML form (check the login page's HTML to determine form encoding).


**Proof:** Username enumeration = measurably different response (body/status/length). Token exposure = token in response body. Token replay = second successful use of a consumed token.


---


Vulnerability Classes in This Skill


1. Username Enumeration via Password Reset

Different error messages for valid vs invalid accounts leaks the user list without authentication. Even timing differences (fast "no user found" vs slow "email queued") count.


High-value targets: admin accounts, employee email patterns, API keys derived from usernames.


2. Weak / Predictable Reset Tokens

A reset token derived from timestamp, username, or sequential IDs can be brute-forced:

- `base64(email + timestamp)` — decodable

- 4-6 digit numeric code — 10K guesses, easily feasible with no rate limit

- Sequential `token=1234`, `token=1235` — trivially enumerable


3. Token Not Bound to Session or IP

Most apps generate a token, email it, and accept it from any browser. A truly bound token should only work from the same IP or require the original session cookie. If neither is enforced → link forwarding = account takeover.


**Token leak via `Referer` / third-party resources.** When the token rides in the reset-page URL (`/reset

🎯 Best For

  • Claude users
  • Software engineers
  • Development teams
  • Tech leads

💡 Use Cases

  • Code quality improvement
  • Best practice enforcement

📖 How to Use This Skill

  1. 1

    Install the Skill

    Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.

  2. 2

    Load into Your AI Assistant

    Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.

  3. 3

    Apply hunt-forgot-password to Your Work

    Open your project in the AI assistant and ask it to apply the skill. Start with a small module to verify the output quality.

  4. 4

    Review and Refine

    Review AI suggestions before committing. Run tests, check for regressions, and iterate on the skill output.

❓ Frequently Asked Questions

Is hunt-forgot-password compatible with Cursor and VS Code?

Yes — this skill works with any AI coding assistant including Cursor, VS Code with Copilot, and JetBrains IDEs.

Do I need specific dependencies for hunt-forgot-password?

Check the install command and Works With section. Most code skills only require the AI assistant and your codebase.

How do I install hunt-forgot-password?

Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/hunt-forgot-password/SKILL.md, ready to use.

Can I customize this skill for my team?

Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.

⚠️ Common Mistakes to Avoid

Skipping validation

Always test AI-generated code changes, even for simple refactors.

Missing dependency updates

Check if the skill requires updated dependencies or new packages.

🔗 Related Skills