hunt-captcha-bypass
Hunt CAPTCHA Bypass — 6 distinct patterns: (1) CAPTCHA field simply omitted from the request (server-side validation absent), (2) CAPTCHA token replayed from a solved challenge (no single-use enforcement), (3) CAPTCHA response accepted on a different endpoint than it was solved on (no binding to act…
Install / Use
npx skills add elementalsouls/Claude-BugHunter --skill hunt-captcha-bypassInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Tags
Our assessment of hunt-captcha-bypass
hunt-captcha-bypass scores 91/100 on our quality scale, 571st of 3,055 Development & Engineering skills we index (top 19%).
Its SKILL.md is 6.0 KB long, well organised into 9 sections with 1 code example: a thorough specification that gives an agent plenty to work with.
With 4,669 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 2 days ago, so hunt-captcha-bypass is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-09-28. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
hunt-captcha-bypass compared with similar skills
All 4 of these similar skills score higher than hunt-captcha-bypass; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hunt-captcha-bypass (this skill)by elementalsouls | 91 | 4.7k | 2d ago | SKILL.md |
| ai-job-searchby MadsLorentzen | 100 | 44.3k | today | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | 2d ago | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 5d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 5d ago | SKILL.md |
Frequently asked questions
- How do I install hunt-captcha-bypass?
- Run
npx skills add elementalsouls/Claude-BugHunter --skill hunt-captcha-bypass. The install tabs above show the steps for each supported agent. - Which AI agents does hunt-captcha-bypass work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is hunt-captcha-bypass safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hunt-captcha-bypass still maintained?
- The repository was last updated 2 days ago, so hunt-captcha-bypass is actively maintained.
Skill content
View source on GitHubname: hunt-captcha-bypass description: "Hunt CAPTCHA Bypass — 6 distinct patterns: (1) CAPTCHA field simply omitted from the request (server-side validation absent), (2) CAPTCHA token replayed from a solved challenge (no single-use enforcement), (3) CAPTCHA response accepted on a different endpoint than it was solved on (no binding to action/session), (4) static or predictable CAPTCHA values accepted (e.g. '0', 'null', empty string), (5) audio/accessibility CAPTCHA trivially solvable programmatically, (6) CAPTCHA only enforced after N failures (first N requests bypass it). Detection: intercept a successful form submission, remove the CAPTCHA field entirely, replay — if it still succeeds, server-side validation is absent. Medium severity standalone; High when it removes the only rate-limit gate protecting a login, registration, or payment endpoint." sources: public_research, operator_experience report_count: 6
Autonomous Testing Priority
The fastest test: just omit the CAPTCHA field entirely. Most CAPTCHA bypass bugs are client-side-only validation.
Pattern 1 — Omit the CAPTCHA field (most common, most automatable):
- GET the form/endpoint that shows a CAPTCHA to understand its field name (usually
g-recaptcha-response,captcha,captcha_token,captcha_answer,h-captcha-response) - POST the form with ALL fields EXCEPT the CAPTCHA field
- If the action succeeds (200, redirect, or "success" message) → no server-side CAPTCHA validation
- Proof: the state-changing action completes without a valid CAPTCHA field (compare against a baseline request that includes it)
Pattern 2 — Empty or null CAPTCHA value:
Instead of omitting the field entirely, include it with an empty string, null, 0, or undefined:
captcha=&email=test@example.com&password=test123
Some apps validate field presence but not content.
Pattern 3 — Replay a previously solved CAPTCHA token:
- Complete one legitimate CAPTCHA challenge and capture the
g-recaptcha-responsetoken - Submit a second request immediately with the SAME token value
- If the second submission also succeeds → token is not single-use (replay attack)
- A replayed token can be shared across automated requests
Pattern 4 — Test without CAPTCHA on similar endpoints:
Some apps add CAPTCHA to the registration form but forget the password reset, API endpoint, or mobile API path (/api/register vs /register). Try the same action via the API path without any CAPTCHA field.
Pattern 5 — Rate/throughput-gated "prove you're automated" challenges: Some apps define CAPTCHA "bypass" as simply exceeding the rate a human could plausibly sustain — e.g. "N submissions within T seconds" — checked by a middleware that counts REQUESTS REACHING the route, not successful outcomes. Garbage/placeholder payloads satisfy this exactly as well as valid ones, since the counter increments regardless of whether the request's own validation passes.
Timing note (sliding-window counters): don't solve this one request at a time — a sequential
pace (seconds between each request) structurally cannot land N requests inside a short sliding
window, and issuing more requests serially does not fix it. A typical failing pattern is 12
requests spread across ~250 seconds when the check requires ~10 requests within 20 seconds.
Instead fire the requests concurrently (e.g. "concurrency": N on a single request call, or
any parallel-request primitive your tooling offers, with N >= the required count) so they arrive
simultaneously and satisfy the sliding window trivially. Check the endpoint's own
required-field validation first (e.g. a rating field that can't be null) so the concurrent
payload is at least well-formed enough to reach the counting middleware, even if other fields
(like the CAPTCHA answer itself) are wrong or reused.
What to skip in automated testing: Solving real reCAPTCHA/hCaptcha programmatically (OCR, audio bypass) requires external services. Only attempt if patterns 1-4 fail and the test budget allows.
Proof: Any successful state-changing action (account created, login succeeded, form submitted) that completed without a valid CAPTCHA token confirms the bypass.
Vulnerability Classes in This Skill
1. Client-Side-Only CAPTCHA Validation
JavaScript hides/disables the submit button until CAPTCHA is solved, but the server never checks the CAPTCHA token. Direct API calls bypass the UI gate entirely.
2. CAPTCHA Not Tied to Session or Action
A token solved for login is accepted on the registration endpoint (or any other). The server validates "is this a real CAPTCHA solution?" but not "is this the right solution for THIS action?".
3. Single-Use Not Enforced
CAPTCHA tokens (especially reCAPTCHA v2) are meant to be consumed after one use. If the server doesn't revoke them after verification, a single human-solved token becomes reusable for many requests.
4. CAPTCHA Added Reactively (Only After N Failures)
Some apps only show CAPTCHA after 3-5 failed login attempts. Before that threshold, no CAPTCHA is required → an attacker can make N-1 attempts per account indefinitely by resetting state between attempts.
5. Static or Predictable CAPTCHA
Math CAPTCHAs (3 + 4 = ?), simple image CAPTCHAs, or text CAPTCHAs with a finite answer set can be automated. These are custom CAPTCHA implementations, not Google/hCaptcha.
Impact Chain
CAPTCHA bypass alone: Medium (enables automation of rate-limited actions)
CAPTCHA bypass + login endpoint = brute force gate removed → chain with hunt-brute-force → High/Critical
CAPTCHA bypass + registration endpoint = account farming → abuse, spam, resource exhaustion
CAPTCHA bypass + password reset = token flooding → chain with hunt-forgot-password
Related Skills
hunt-brute-force— CAPTCHA is often the only rate-limit gate; bypass unlocks brute forcehunt-forgot-password— reset endpoints sometimes protected by CAPTCHA onlyhunt-race-condition— race the CAPTCHA validation window (submit before the token is revoked)
Related Skills
ai-job-search
44.3kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
