authentication
Authentication security testing - auth bypass, JWT attacks, OAuth flaws, password attacks, 2FA bypass, CAPTCHA bypass, and bot detection evasion.
How do I install this agent skill?
npx skills add https://github.com/transilienceai/communitytools --skill authenticationIs this agent skill safe to install?
- Gen Agent Trust Hubfail
The skill is a comprehensive authentication security testing toolkit containing reference guides and helper scripts. It includes information on JWT, OAuth, 2FA bypass, and password attacks. While scanners flagged some content as potentially malicious, these findings are consistent with offensive security documentation, such as phishing examples and disposable email services. The included tools for credential management follow security best practices by using restricted file permissions and gitignore patterns for local data storage.
- Socketfail
34 alerts: gptSecurity, gptAnomaly, gptMalware
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Authentication
Test authentication mechanisms including login security, token handling, 2FA, CAPTCHA, and bot detection.
Techniques
| Type | Key Vectors |
|---|---|
| Auth Bypass | Default credentials, logic flaws, response manipulation |
| ADFS/SAML | Golden SAML, token signing cert theft, assertion manipulation, SAML wrapping |
| JWT | Algorithm confusion, key injection, claim tampering, token forging |
| OAuth | Redirect manipulation, CSRF, token leakage, scope abuse |
| Password | Brute force, credential stuffing, password policy bypass |
| 2FA Bypass | Response manipulation, direct endpoint access, code reuse, race conditions |
| CAPTCHA Bypass | Missing server validation, token reuse, OCR, parameter manipulation |
| Bot Detection | Behavioral biometrics simulation, fingerprint randomization, stealth mode |
Tools
PasswordGenerator (tools/password_generator.py):
from tools.password_generator import generate_password
password = generate_password(hint_text="8-16 chars, uppercase, numbers")
CredentialManager (tools/credential_manager.py):
from tools.credential_manager import CredentialManager
mgr = CredentialManager()
mgr.store_credential(target="example.com", username="test", password="pass")
Workflow
- Analyze auth implementation (forms, tokens, 2FA, CAPTCHA)
- Test bypass vectors per technique type
- Use Playwright MCP with human-like behavior (typing 80-200ms, random pauses)
- Capture evidence (screenshots, network logs, tokens)
- Document findings with PoC scripts
Reference
reference/authentication*.md- Auth bypass techniques, payloads, and resourcesreference/jwt*.md- JWT attack techniques and cheat sheetsreference/oauth*.md- OAuth vulnerability testingreference/scenarios/password-attacks/*.md- Password attack vectors (spray, stuffing, cracking, PtH)reference/adfs-exploitation.md- ADFS, Golden SAML, federation attacksreference/scenarios/2fa/*.md- 2FA bypass methodsreference/CAPTCHA_BYPASS.md- 11 CAPTCHA bypass techniquesreference/BOT_DETECTION.md- Bot detection evasion strategiesreference/PASSWORD_CREDENTIAL_MANAGEMENT.md- Tool usage guide
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/transilienceai/communitytools/authentication">View authentication on skillZs</a>