CtrlK
BlogDocsLog inGet started
Tessl Logo

hunt-mfa-bypass

Hunt MFA / 2FA bypass — 7 distinct patterns. (1) MFA not enforced on sensitive endpoints (password change, email change accept without MFA challenge), (2) MFA-step skip via direct navigation to post-login URL, (3) MFA-token replay (same code accepted twice), (4) brute-force the 6-digit OTP without rate limit (10^6 attempts at server speed), (5) race condition on OTP validation, (6) recovery-code dump via /api/me, (7) backup factor downgrade (SMS factor with no rate limit). Plus the chain: cookie theft + password oracle + no step-up = ATO without MFA challenge. Detection: trace auth flow in Burp, find every state transition, check if MFA is middleware-gated vs per-endpoint, check OTP entropy and rate limit on OTP-validate. Validate: attacker session reaching post-MFA state. Use when hunting auth bypass, MFA flows, chaining primitives toward ATO.

67

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, highly actionable hunting skill with copy-paste tooling and clear validation checkpoints. Its main weakness is conciseness: the seven MFA-bypass patterns are presented twice in overlapping sections, inflating the token budget.

Suggestions

Consolidate the 'Autonomous Testing Priority' and '19. MFA / 2FA BYPASS' sections so each pattern is documented once; merge the workflow-bypass framing into the canonical pattern list to remove duplication.

Fix the orphaned '19.' section numbering (there is no preceding numbered list) so the document hierarchy is unambiguous.

For Pattern 4 (prefix oracle), add an explicit validate→fix→retry loop (e.g., 'if no prefix leaks, fall back to Pattern 2/3') to tighten workflow clarity for the batch brute-force path.

DimensionReasoningScore

Conciseness

Mostly efficient and assumes Claude's domain knowledge, but the same seven patterns are described twice in different framings across the 'Autonomous Testing Priority' and '19. MFA / 2FA BYPASS' sections, adding redundant tokens that could be consolidated.

3 / 5

Actionability

Provides fully executable, copy-paste-ready guidance including an ffuf brute-force command with rate-limit flags, a curl skip-MFA probe, and a complete Python asyncio race script, covering the common cases.

5 / 5

Workflow Clarity

Patterns are sequenced with conditional feedback ('If accepted →', 'If the response returns user data →') and explicit Proof/Validate checkpoints plus a brute-force precondition guard; only a minor validate→fix→retry loop is absent.

4 / 5

Progressive Disclosure

No bundle files exist; content is organized under clear section headers with one-level cross-skill references, though the dual pattern listings and stray '19.' numbering are minor organization gaps.

4 / 5

Total

16

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, third-person description that enumerates concrete patterns and provides an explicit 'Use when' trigger clause. It is comprehensive on what/when with only minor jargon and a slight overlap risk on the 'auth bypass' trigger.

DimensionReasoningScore

Specificity

Lists multiple concrete actions across 7 distinct patterns plus specific detection steps ('trace auth flow in Burp', 'check OTP entropy and rate limit on OTP-validate') and a concrete validation criterion, giving comprehensive coverage with no real gaps.

5 / 5

Completeness

Explicitly answers both what (7 enumerated patterns, detection, validation) and when via a concrete 'Use when hunting auth bypass, MFA flows, chaining primitives toward ATO' trigger clause.

5 / 5

Trigger Term Quality

Strong natural keywords ('MFA / 2FA bypass', 'auth bypass', 'MFA flows', 'OTP') with the MFA/2FA synonym pair covered, but 'chaining primitives toward ATO' is jargon and common phrasings like 'two-factor authentication' and 'login bypass' are absent.

4 / 5

Distinctiveness Conflict Risk

The MFA/2FA-bypass niche is clearly distinct, but the 'Use when hunting auth bypass' trigger creates minor overlap risk with a general auth-bypass skill.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.