skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
transilienceai/communitytools170 installs

authentication

Authentication security testing - auth bypass, JWT attacks, OAuth flaws, password attacks, 2FA bypass, CAPTCHA bypass, and bot detection evasion.

How do I install this agent skill?

npx skills add https://github.com/transilienceai/communitytools --skill authentication
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubfail

    The skill is a comprehensive authentication security testing toolkit containing reference guides and helper scripts. It includes information on JWT, OAuth, 2FA bypass, and password attacks. While scanners flagged some content as potentially malicious, these findings are consistent with offensive security documentation, such as phishing examples and disposable email services. The included tools for credential management follow security best practices by using restricted file permissions and gitignore patterns for local data storage.

  • Socketfail

    34 alerts: gptSecurity, gptAnomaly, gptMalware

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

Authentication

Test authentication mechanisms including login security, token handling, 2FA, CAPTCHA, and bot detection.

Techniques

TypeKey Vectors
Auth BypassDefault credentials, logic flaws, response manipulation
ADFS/SAMLGolden SAML, token signing cert theft, assertion manipulation, SAML wrapping
JWTAlgorithm confusion, key injection, claim tampering, token forging
OAuthRedirect manipulation, CSRF, token leakage, scope abuse
PasswordBrute force, credential stuffing, password policy bypass
2FA BypassResponse manipulation, direct endpoint access, code reuse, race conditions
CAPTCHA BypassMissing server validation, token reuse, OCR, parameter manipulation
Bot DetectionBehavioral biometrics simulation, fingerprint randomization, stealth mode

Tools

PasswordGenerator (tools/password_generator.py):

from tools.password_generator import generate_password
password = generate_password(hint_text="8-16 chars, uppercase, numbers")

CredentialManager (tools/credential_manager.py):

from tools.credential_manager import CredentialManager
mgr = CredentialManager()
mgr.store_credential(target="example.com", username="test", password="pass")

Workflow

  1. Analyze auth implementation (forms, tokens, 2FA, CAPTCHA)
  2. Test bypass vectors per technique type
  3. Use Playwright MCP with human-like behavior (typing 80-200ms, random pauses)
  4. Capture evidence (screenshots, network logs, tokens)
  5. Document findings with PoC scripts

Reference

  • reference/authentication*.md - Auth bypass techniques, payloads, and resources
  • reference/jwt*.md - JWT attack techniques and cheat sheets
  • reference/oauth*.md - OAuth vulnerability testing
  • reference/scenarios/password-attacks/*.md - Password attack vectors (spray, stuffing, cracking, PtH)
  • reference/adfs-exploitation.md - ADFS, Golden SAML, federation attacks
  • reference/scenarios/2fa/*.md - 2FA bypass methods
  • reference/CAPTCHA_BYPASS.md - 11 CAPTCHA bypass techniques
  • reference/BOT_DETECTION.md - Bot detection evasion strategies
  • reference/PASSWORD_CREDENTIAL_MANAGEMENT.md - Tool usage guide

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/transilienceai/communitytools/authentication">View authentication on skillZs</a>