LogoClawIndex
CasesSkillsAbout
LogoClawIndex

hunt-api-misconfig - Hunt API security misconfigurations

Tests APIs for mass assignment, prototype pollution, parameter pollution, CORS, HTTP verb, OData, and JWT handling weaknesses.

Tags

Updated: 2026-10-03

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Test mass assignment
  • Detect prototype pollution
  • Test parameter pollution
  • Test CORS misconfiguration
  • Test HTTP verb tampering
  • Inspect JWT handling
  • Probe OData filters
  • Compare baseline responses
  • Validate learned sinks

Inputs

  • Target API endpoints
  • HTTP requests
  • Authentication sessions
  • CSRF fields
  • Client-side JavaScript
  • API specifications
  • Baseline responses

Outputs

  • HTTP responses
  • Error messages
  • Unexpected response fields
  • Changed endpoint behavior
  • Exposed sensitive fields
  • Confirmed status changes

Requirements

  • Authorized testing scope
  • HTTP client access
  • Target application access

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
API security
misconfiguration
mass assignment
prototype pollution
parameter pollution
CORS
OData
JWT
Test mass assignment
Detect prototype pollution
Test parameter pollution
Test CORS misconfiguration
Target API endpoints
HTTP requests
Authentication sessions
HTTP responses
Error messages
Unexpected response fields