Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Hunt Race Condition

ASecurity

Hunting playbook for race-condition / TOCTOU vulnerabilities — concurrent-request abuse, HTTP/2 single-packet attacks, double-redeem / double-spend, MFA-OTP & email-verify races, rate-limit bypass. Use when hunting races or TOCTOU bugs.

4 stars
0 votes
0 copies
0 views
Added 9/19/2026
developmentpythondebugginggitapibackendsecurity

Works with

api

Security Analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned 9/19/2026

$npx -y skills add jgamaraalv/delivery-loop --skill hunt-race-condition --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Hunt Race Condition?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Hunt Race Condition
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jgamaraalv-hunt-race-condition/badge)](https://www.skillsdirectory.com/skills/jgamaraalv-hunt-race-condition)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: hunt-race-condition
description: Hunting playbook for race-condition / TOCTOU vulnerabilities — concurrent-request abuse, HTTP/2 single-packet attacks, double-redeem / double-spend, MFA-OTP & email-verify races, rate-limit bypass. Use when hunting races or TOCTOU bugs.
---

# Hunting Race Conditions

A hunting playbook for race-condition / TOCTOU vulnerabilities, built from 12 public bug-bounty and coordinated-disclosure cases. Race conditions are high-severity because they break the financial, access-control, and integrity assumptions defenders rarely stress-test: double-spending credits, inflating votes, bypassing per-user limits, and racing token/state transitions. The enabling primitive for modern targets is the **HTTP/2 single-packet attack**, which collapses the race window to sub-millisecond and makes rate-limited, distributed, load-balanced backends race-able.

## Quick-start

1. **Enumerate one-time / limited-use actions** — every endpoint enforcing "once per user", "limited quantity", or "deduct balance". The gap between its state read and state write is your window.
2. **Capture a clean baseline** request and confirm the expected single-use behaviour.
3. **Stage parallel requests** — prefer Turbo Intruder `Engine.BURP2` (single-packet HTTP/2) when the target advertises `h2`; otherwise fall back to parallel HTTP/1.1.
4. **Fire 10–50 simultaneous requests** with last-byte sync, then look for multiple successes, duplicate effects, or stale-state where only one should have won.
5. **Verify the effect and reproducibility** (3/5 attempts), then run Gate 0 before reporting.

Full detail is loaded on demand — see References.

## References

Each file is loaded on demand — read one only when the task needs that depth (progressive disclosure).

- `references/methodology.md` — crown-jewel targets, attack-surface signals (URLs, headers, JS/tech-stack tells), the 10-step hunting methodology, common root causes, defender bypass techniques, Gate 0 validation, and real impact examples · read when scoping targets, planning the hunt, or validating/writing up a finding.
- `references/payloads.md` — copy-paste Turbo Intruder, `curl`-parallel, and Python `asyncio` race templates, plus source-audit grep patterns and the HTTP/2 capability check · read when you need a ready-to-fire PoC or to audit source for unlocked read-then-write.
- `references/single-packet-attack.md` — the HTTP/2 single-packet deep reference: why it works, last-byte-sync mechanics, Wireshark validation, h2.0 vs h2.cl variants, race-window estimation, connection/stream shapes, the annotated `Engine.BURP2` template, Flatt's first-sequence-sync (N>30), operator playbook, and anti-patterns · read when building or debugging a single-packet exploit or deciding which attack shape to use.
- `references/disclosed-reports.md` — the per-bug-class catalog of the 12 disclosed cases (GitLab CVE-2022-4037, Worldcoin, Stripe ×2, Reverb gift card, Cosmos faucet, InnoGames, Flatt PIN-bruteforce, nopCommerce CVE-2024-58248, …) with payload, root cause, and bounty · read when matching your target to a known race class or citing precedent.

## Related Skills & Chains

- **`hunt-business-logic`** — Race conditions are the "concurrency arm" of every business-logic state machine. Chain primitive: business logic (coupon/promo) + race-condition single-packet attack → coupon redeemed N times → direct financial loss.
- **`hunt-mfa-bypass`** — OTP-expiry windows and replay protection are classic race targets. Chain primitive: race + MFA-validate endpoint → bypass OTP expiry by submitting N concurrent validations within the validity window.
- **`hunt-ato`** — Race conditions on password reset, email change, and account creation enable persistent ATO. Chain primitive: race on email-change endpoint + atomic-update missing → swap victim email + read reset token before user notice.
- **`hunt-api-misconfig`** — Wallet/balance/credit endpoints without atomic UPDATE are double-spend candidates. Chain primitive: race + atomic-update missing → double-spend balance → withdraw N× user balance.
- **`security-arsenal`** — Load the Turbo Intruder single-packet template, h2.cl smuggling for atomic submit, and `curl --next` parallel multi-request patterns.
- **`triage-validation`** — Apply the Statistical-Sampling gate: a single anomalous response is noise; require 1 successful + N duplicate / over-quota / stale-state demonstrations with response screenshots before reporting.

Attribution

jgamaraalvjgamaraalv
View sourceSee grades on GitHubMore from jgamaraalv →
SSkills Directory ProSkills Directory

Get any skill into Claude in one click.

Download any skill as a ZIP for Claude.ai, Claude Desktop, or .claude/skills. $9/mo.

See Pro

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills Directory ProSkills Directory

Get any skill into Claude in one click.

Download any skill as a ZIP for Claude.ai, Claude Desktop, or .claude/skills. $9/mo.

See Pro

Related Skills

Clean Code

Pragmatic coding standards - concise, direct, no over-engineering, no unnecessary comments

304955 votes

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

285172 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2222 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

10311 votes
View all in development →