LogoClawIndex
CasesSkillsAbout
LogoClawIndex

hunt-ato - Hunt account takeover paths and validate exploitability

Tests account-takeover paths across password resets, email changes, MFA, OAuth, sessions, JWTs, recovery flows, and chains with end-to-end impact validation.

Tags

Updated: 2026-10-08
account takeoverweb securitypassword resetOAuthJWTsession securitySSO

Capabilities

Identify reset poisoningTest reset token leakageTest email change re-authenticationAssess JWT trust boundaries

Typical Inputs

Target applicationTest accounts A and BPassword reset endpoints

Typical Outputs

Account takeover validation resultCaptured reset tokensCaptured OAuth codes or tokens

What this skill does

  • Identify reset poisoning
  • Test reset token leakage
  • Test email change re-authentication
  • Assess JWT trust boundaries
  • Test OAuth redirect abuse
  • Test recovery-question abuse
  • Test SSO subdomain takeover
  • Chain takeover primitives
  • Validate takeover impact

Inputs

  • Target application
  • Test accounts A and B
  • Password reset endpoints
  • Email change endpoints
  • MFA and OAuth endpoints
  • Session and JWT tokens
  • Controlled victim inbox
  • Out-of-band callback server
  • Candidate token lists
  • DNS or cloud provider access

Outputs

  • Account takeover validation result
  • Captured reset tokens
  • Captured OAuth codes or tokens
  • Privileged endpoint responses
  • Changed test-account credentials
  • Account takeover severity

Requirements

  • Authorized target access
  • Permission to test both accounts
  • HTTP testing client
  • Browser with network inspection
  • Out-of-band callback infrastructure
  • DNS or cloud provider account for takeover testing

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.