Install the "authbypass-authentication-flaws" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/authbypass-authentication-flaws into .claude/skills/authbypass-authentication-flaws/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authbypass-authentication-flaws", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill authbypass-authentication-flaws -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "authbypass-authentication-flaws" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/authbypass-authentication-flaws into .agents/skills/authbypass-authentication-flaws/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authbypass-authentication-flaws", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill authbypass-authentication-flaws -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "authbypass-authentication-flaws" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/authbypass-authentication-flaws into .cursor/skills/authbypass-authentication-flaws/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authbypass-authentication-flaws", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill authbypass-authentication-flaws -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "authbypass-authentication-flaws" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/authbypass-authentication-flaws into .gemini/skills/authbypass-authentication-flaws/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authbypass-authentication-flaws", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill authbypass-authentication-flaws -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "authbypass-authentication-flaws" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/authbypass-authentication-flaws into .github/skills/authbypass-authentication-flaws/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authbypass-authentication-flaws", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill authbypass-authentication-flaws -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "authbypass-authentication-flaws" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/authbypass-authentication-flaws into .opencode/skills/authbypass-authentication-flaws/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "authbypass-authentication-flaws", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
authbypass-authentication-flaws
GitHub stars
135
Used in
1 other repo
Token cost
~3.9k tokens
SKILL.md length
995 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
Apache-2.0
At a glance
Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.
Works in 12 steps: AUTHORIZED CREDENTIAL TEST PLANNING → SQL INJECTION LOGIN BYPASS → PASSWORD RESET VULNERABILITIES → …
Assessing login flows
SKILL.md covers 0. AUTHORIZED CREDENTIAL TEST…, 1. SQL INJECTION LOGIN BYPASS, 2. PASSWORD RESET… and 3. ACCOUNT ENUMERATION, plus 3 more sections
Needs VICTIM_TOKEN
What it does
Authbypass Authentication Flaws is an agent skill from langbyyi/CyberStrikeAI-SRC. Authentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token predictability, brute-force resistance, and session boundary flaws.
Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Authentication. It works with MySQL. The licence is Apache-2.0.
When your agent uses it
Assessing login flows
Password reset logic
Account recovery
Token predictability
Example prompts
“/authbypass-authentication-flaws”
Requirements
A credential in VICTIM_TOKEN
Workflow steps
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 166ee1c. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
No scripts in the folder and no shell commands in SKILL.md (its code samples are sql, http, bash and php).
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names these keys or tokens, usually read from environment variables:
VICTIM_TOKEN
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Authbypass Authentication Flaws loads about 3.9k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 995 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~57
When it runs· the whole SKILL.md, loaded when a task matches
~3.9k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Classic but still found in legacy systems, custom ORMs, and raw query code:
sql
-- Basic bypass (admin user assumed first row):
Username: admin'--
Password: anything
→ Query: SELECT * FROM users WHERE user='admin'--' AND pass='anything'
-- Generic bypass (logs in as first user in DB):
Username: ' OR '1'='1'--
Password: anything
→ Query: SELECT * FROM users WHERE user='' OR '1'='1'--' AND pass='anything'
-- Blind: does this work?
Username: ' OR 1=1--
Username: admin' OR 'a'='a
Username: 1' OR '1'='1'/*
Username: 1 or 1=1
Test each field separately — only one field may be vulnerable.
Invalid username → fast response (no DB lookup)
Valid username → slightly slower (DB lookup + hash comparison)
→ Timing oracle
Password Reset Flow
POST /forgot-password {"email": "nonexistent@example.com"}
→ "If this email exists, we sent a reset link" (proper)
vs.
→ "This email is not registered" (enumeration possible)
Registration Endpoint
POST /register {"email": "victim@example.com"}
→ "Email already registered" → confirms account exists
vs.
→ "Verification email sent" for both → no enumeration
4. BRUTE FORCE BYPASS
Lockout After N Attempts Then Resets
Lockout at 10 attempts → try 9 wrong passwords → lock
Wait for reset period (usually 30 min or 1 hour)
→ Try 9 more → repeat → no permanent lockout
IP-Based Lockout Bypass
X-Forwarded-For: 1.1.1.1 ← change each request
X-Real-IP: 2.2.2.2
Rotate through IPs in header
Username Cycling vs Password Cycling
Normal brute: try many passwords for one user → lock
Reverse brute: try ONE password for many users
→ "password123" against all users → find those with weak password
→ No single account locked out
Credential Stuffing
Use breached credentials from HaveIBeenPwned datasets against target:
Flow: Login (password correct) → redirect to 2FA page → enter code
Attack: After password step, session cookie is set but 2FA not yet checked.
→ Use session cookie to directly access /dashboard
→ Skip 2FA page entirely
2FA Code Brute Force
4-6 digit TOTP codes = 1,000,000 possibilities max
If no lockout on 2FA step:
→ Brute force all codes (tool: Burp Intruder, sequential)
→ TOTP windows: 30-second window, some accept previous/next window
2FA on Critical Actions Not On Login
Login doesn't require 2FA, but:
DELETE /account or POST /transfer requires 2FA
Attack: Is 2FA checked on those actions or only on login?
→ If only login: log in once → no 2FA needing verification for actions
2FA Backup Code Abuse
Generate backup codes (usually 8-10 single-use)
Test:
→ Are backup codes rate-limited?
→ Can backup codes be used multiple times?
→ Short codes (6-8 chars)? Brute-force if no rate limit
2FA Code Reuse
TOTP codes valid for one use
→ Use same TOTP code twice → does second use work?
→ Replay attack if server doesn't track used codes
6. OAUTH / SSO ACCOUNT TAKEOVER PATTERNS
Email Claim Trust
1. Create account at attacker-controlled OAuth provider
2. Set email claim = victim@target.com
3. Link/login via that provider
→ If server trusts email claim without verification → account merge/takeover
Password Doesn't Apply After SSO Link
1. User links Google SSO
2. User forgets password (account has no password set after SSO only)
3. "Forgot Password" flow → resets password even for SSO-only accounts?
→ Can set password → now bypass SSO → direct login
7. USERNAME / PASSWORD FIELD MANIPULATION
Long Password DoS → Bypass
Some apps hash passwords before sending to database.
bcrypt has 72-byte limit — input beyond 72 bytes is ignored.
Attack:
→ Register with password "A"*100
→ Login with password "A"*72 → same hash → works
→ Login with "A"*71 + "totally different" → if truncation → same hash if first 72 chars match
Null Byte in Username
username=admin%00 vs username=admin
→ Null byte truncation in some string comparisons
→ "admin\0attacker" = "admin" in C-string comparison
Unicode Normalization
Username: "ⓢcott" → normalizes to "scott" → impersonates "scott"
Username: "admin" (various Unicode homoglyphs for letters a,d,m,i,n)
8. SESSION MANAGEMENT FLAWS
Session Not Invalidated on Logout
1. Log in → capture session cookie
2. Log out
3. Replay captured session cookie → still valid?
→ Session not server-side invalidated
Session Not Regenerated on Privilege Change
1. Log in as low priv → get session cookie
2. Admin upgrades your role
3. Old session cookie now has admin access?
→ Session not regenerated → old token inherits new privileges
Predictable Session Tokens
Token: base64(userid+timestamp) → reversible
Token: sequential integers → session ID= your_session_id -/+ small number
Token: short random (32-bit entropy) → brute-forceable
9. AUTHENTICATION TESTING CHECKLIST
□ Try SQL injection on login fields (' OR 1=1--)
□ Test password reset: predict token, host header injection, Referer leak
□ Test account enumeration via error messages / timing
□ Check 2FA: skip step (direct URL), brute force codes, reuse codes
□ Test brute force protections: X-Forwarded-For bypass, reverse brute
□ Check session invalidation on logout
□ Check session regeneration after privilege change
□ Test password change requiring current password
□ Test long passwords (bcrypt 72-byte truncation)
□ OAuth/SSO: test email claim trust, password set after SSO
□ Check remember_me tokens: how long, revocable, predictable?
10. PASSWORD RESET ATTACK MATRIX (22 Patterns)
#
Pattern
Description
1
Predictable reset token
Token based on timestamp, user ID, or sequential number
2
Token not bound to user
Use token generated for user A to reset user B
3
Token in response body
Reset token returned in HTTP response (not just email)
4
Token in URL parameter
Reset link token visible in Referer header to external resources
5
No token expiration
Token remains valid indefinitely
6
Token reuse
Same token works multiple times
7
Short/brute-forceable token
4-6 digit numeric code without rate limiting
8
Password reset via host header
Host: attacker.com → reset link sent with attacker's domain
9
Registration overwrites existing account
Register with same email → overwrites password
10
Step skip (frontend only)
Jump directly to "set new password" step via URL
11
Response manipulation
Change {"status":"fail"} to {"status":"success"} in proxy
12
Verification code in response
SMS/email code returned in API response
13
Parallel session reset
Start reset for A, complete with B's session
14
Email/phone parameter pollution
email=victim@x.com&email=attacker@x.com
15
Unicode normalization
admin@target.com vs ADMIN@target.com vs Unicode confusables
16
SQL injection in reset
Email field injectable in reset query
17
IDOR on reset endpoint
Change user ID in reset confirmation request
18
Cross-protocol reset
Mobile API doesn't validate same token as web
19
Default security questions
Guessable answers, no rate limit
20
Token generation race condition
Multiple simultaneous requests generate same token
+1234567890%00 bypasses dedup but delivers to same number
17
Case sensitivity
Email: Admin@X.com vs admin@x.com
18
Space/encoding in identifier
user@x.com vs user@x.com (trailing space)
19
Concurrent requests
Race condition: send verify before captcha loads
20
Third-party captcha bypass
Misconfigured reCAPTCHA site key allows any domain
12. INSECURE RANDOMNESS — TOKEN PREDICTION
UUID v1 (Time-Based — Predictable!)
UUID v1 format: timestamp-clock_seq-node(MAC)
# MAC address often leaked via other endpoints
# Timestamp is 100ns intervals since 1582-10-15
# Tool: guidtool (reconstruct possible UUIDs from known timestamp range)
MongoDB ObjectId
ObjectId = 4-byte timestamp + 5-byte random + 3-byte counter
# First 4 bytes = Unix timestamp → creation time leaked
# Counter is sequential → adjacent ObjectIds predictable
# If you know one ObjectId, nearby ones are calculable
PHP uniqid()
php
uniqid() = hex(microtime)
// Output: 5f3e7a4c1d2b3
// Entirely based on current microsecond timestamp
// Predictable if you know approximate server time
PHP mt_rand() Recovery
# mt_rand() uses Mersenne Twister PRNG
# After observing ~624 outputs, full internal state is recoverable
# Tool: openwall/php_mt_seed
# Feed known outputs → recover seed → predict all future values
Tools
guidtool — UUID v1 reconstruction
AethliosIK/reset-tolkien — Automated token prediction for password resets
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in langbyyi/CyberStrikeAI-SRC, which our catalogue first saw on October 7, 2026.
Authbypass Authentication Flaws next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Authbypass Authentication Flaws compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Authbypass Authentication Flaws this skilllangbyyi/CyberStrikeAI-SRC
Spring Boot 项目一键初始化技能。面向零基础小白,提供环境探测、自动安装、完整 Web 骨架生成、SSE 流式框架、JWT 鉴权、统一响应封装、文件上传接口、一键启动/重启脚本、Swagger 文档,内置 MySQL(默认)/ PostgreSQL / MongoDB 数据库选择。用户只需说"帮我搭一个 Spring Boot…
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC. Authbypass Authentication Flaws is an agent skill from langbyyi/CyberStrikeAI-SRC. Authentication bypass testing playbook.
When should I use Authbypass Authentication Flaws?
How do I install Authbypass Authentication Flaws in Claude Code?
Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill authbypass-authentication-flaws -a claude-code`. Or copy the skill folder (skills/authbypass-authentication-flaws in langbyyi/CyberStrikeAI-SRC) into .claude/skills/authbypass-authentication-flaws in your project. Claude Code loads it when a task matches its description.
How do I install Authbypass Authentication Flaws in Codex?
Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill authbypass-authentication-flaws -a codex`. Or copy the skill folder (skills/authbypass-authentication-flaws in langbyyi/CyberStrikeAI-SRC) into .agents/skills/authbypass-authentication-flaws in your project. Codex loads it when a task matches its description.
Can I use Authbypass Authentication Flaws in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbyyi/CyberStrikeAI-SRC --skill authbypass-authentication-flaws -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authbypass-authentication-flaws, .gemini/skills/authbypass-authentication-flaws, .github/skills/authbypass-authentication-flaws and .opencode/skills/authbypass-authentication-flaws in your project.
What does Authbypass Authentication Flaws need to run?
Going by SKILL.md and its folder, Authbypass Authentication Flaws needs credentials named VICTIM_TOKEN. Our summary lists: A credential in VICTIM_TOKEN.
Does Authbypass Authentication Flaws access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Authbypass Authentication Flaws safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Authbypass Authentication Flaws use?
Authbypass Authentication Flaws is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Authbypass Authentication Flaws use?
About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Authbypass Authentication Flaws?
Skills that share tags, products or a category with Authbypass Authentication Flaws: Edgeone Pages Website Skeleton (TencentEdgeOne/awesome-website-prompts-and-skills, 183 stars), Fastapi Init Skill (jiushiwon/wg-skills, 114 stars), Springboot Init Skill (jiushiwon/wg-skills, 114 stars) and Fortify Development (coollabsio/coolify, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Authbypass Authentication Flaws?
langbyyi (a GitHub user) maintains it in langbyyi/CyberStrikeAI-SRC, which has 135 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 7, 2026.
Source: langbyyi/CyberStrikeAI-SRC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.