Back to Skills

csrf-cross-site-request-forgery

CSRF testing playbook. Use when reviewing state-changing web flows, anti-CSRF defenses, SameSite behavior, JSON CSRF, login CSRF, and OAuth state handling.

1,281stars175forksUpdated 7/5/2026

Security Assessment

Low Risk(70/100)

Detected risks:

Secret Exposure([SKILL.md] Token =, [SKILL.md] token =, [SKILL.md] token=)
Security Score70/100

About csrf-cross-site-request-forgery

An expert attack playbook for testing Cross-Site Request Forgery in state-changing web flows. It is meant for reviewing anti-CSRF defenses, SameSite cookie behavior, JSON and multipart CSRF, login CSRF, and OAuth state handling, and deliberately goes beyond textbook CSRF to cover modern bypass vectors and commonly broken token implementations that base models overlook.

It opens by defining the core preconditions for exploitability - an authenticated victim, session identification by cookie alone, an attacker-constructable request, and cookies that travel cross-origin - then lists high-value state-changing endpoints worth targeting, such as password and email changes, role changes, transfers, two-factor disabling, and API-key or webhook configuration. A large section catalogs token bypasses: no token present, tokens that exist but are never validated server-side, tokens bound to a session but not a user, token-in-cookie-only designs, static or predictable tokens, and broken double-submit-cookie patterns exploitable through subdomain cookie tossing. SameSite handling gets its own treatment, including Lax bypass via GET, using subdomain XSS as a same-site staging point, SameSite=None, and Chrome's roughly two-minute Lax exemption race window.

Ready-to-use proof-of-concept templates cover simple and auto-submitting form POSTs, GET-based attacks via image tags, and custom-header XHR. Dedicated sections address JSON CSRF through credentialed fetch when CORS is misconfigured, the text/plain Content-Type downgrade trick, multipart CSRF, and combining CSRF with XSS to read a real token from the DOM and bypass otherwise solid protection. A final section covers OAuth CSRF caused by a missing state parameter, which can silently link a victim account to the attacker's identity provider. A testing checklist and cross-references to related CORS and OAuth/OIDC skills round out the workflow, which targets offensive security review and authorized testing.

FAQ

What conditions make an endpoint vulnerable to CSRF?

The victim must be authenticated with a session cookie, the server must identify the session by cookie alone, the attacker must be able to construct the request, and the cookie must be sent cross-origin (SameSite=None or legacy behavior).

Does it cover SameSite cookie bypasses?

Yes, including SameSite=Lax bypass via the GET method, using subdomain XSS as a same-site staging point, SameSite=None, and Chrome's roughly two-minute Lax exemption race window for freshly set cookies.

Can CSRF work against JSON APIs?

It can, via a credentialed fetch when CORS is misconfigured to allow credentials, or a Content-Type downgrade to text/plain when the server still parses the body as JSON.

Which token bypasses does it check for?

Missing tokens, tokens never validated server-side, tokens tied to a session but not a user, token-in-cookie-only designs, and static or predictable tokens, plus broken double-submit-cookie patterns.

How does OAuth relate to CSRF here?

A missing state parameter enables OAuth CSRF, where a victim's browser exchanges an attacker's authorization code and their account gets linked to the attacker's OAuth provider.

Install csrf-cross-site-request-forgery

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill