CSRF specialist (H1 #57). Use for testing state-changing actions without proper token validation, SameSite cookie bypass, and CSRF in JSON/API endpoints.
$curl -o .claude/agents/csrf-hunter.md https://raw.githubusercontent.com/h-mmer/pentest-agents/HEAD/.claude/agents/csrf-hunter.mdInstalls into the current project.
Install csrf-hunter by running `curl -o .claude/agents/csrf-hunter.md https://raw.githubusercontent.com/h-mmer/pentest-agents/HEAD/.claude/agents/csrf-hunter.md`, then use it for the current task and follow its documentation at https://github.com/h-mmer/pentest-agents.