This skill enables Claude to validate authentication implementations against security best practices and industry standards. It analyzes various authentication methods, including JWT, OAuth, session-based authentication, and API keys. Use this skill when you need to perform an authentication security check, assess password policies, evaluate MFA implementation, or analyze session security. Trigger this skill with phrases like "validate authentication," "authentication check," or "authcheck."
81
53%
Does it follow best practices?
Impact
83%
1.07xAverage score across 15 eval scenarios
Passed
No known issues
Optimize this skill with Tessl
npx tessl skill review --optimize ./backups/skills-migration-20251108-070147/plugins/security/authentication-validator/skills/authentication-validator/SKILL.mdJWT security report structure
Password security section
87%
100%
Session management section
33%
50%
Token security section
87%
100%
MFA section
0%
100%
Account security section
0%
100%
Signing algorithm check
41%
50%
Expiration claim check
100%
100%
Audience/issuer validation check
0%
100%
Short-lived token recommendation
100%
100%
Refresh token rotation recommendation
25%
100%
bcrypt or Argon2 recommendation
100%
100%
Session cookie security checks
Password security section
0%
16%
Session management section
66%
100%
Token/auth security section
50%
66%
MFA section
0%
0%
Account security section
33%
50%
HttpOnly attribute check
50%
100%
Secure attribute check
100%
100%
SameSite attribute check
100%
100%
Session fixation check
100%
100%
CSRF vulnerability check
100%
100%
MFA recommendation
0%
0%
Password hashing and token rotation
Password security section
100%
100%
Session management section
40%
100%
Token security section
100%
100%
MFA section
0%
100%
Account security section
40%
100%
bcrypt recommendation
100%
100%
Argon2 recommendation
100%
100%
Salt generation note
100%
100%
Short-lived token recommendation
100%
100%
Refresh token rotation
100%
100%
MFA recommendation
0%
100%
No rotation in current impl
100%
100%
OAuth 2.0 authentication analysis
Password security section
40%
80%
Session management section
80%
100%
Token security section
87%
100%
MFA section
0%
0%
Account security section
20%
80%
State parameter check
100%
100%
PKCE check
78%
100%
Redirect URI check
0%
0%
Implicit flow deprecation
100%
100%
Short-lived token recommendation
22%
0%
MFA recommendation
0%
0%
API key authentication analysis
Password security section
100%
100%
Session management section
20%
20%
Token security section
100%
100%
MFA section
0%
0%
Account security section
100%
60%
Plaintext key storage
100%
100%
Keys in URL parameters
100%
100%
No key rotation
58%
16%
No scope restriction
100%
100%
bcrypt or Argon2 recommendation
100%
100%
MFA recommendation
0%
0%
MFA and account security checks
Password security section
100%
100%
Session management section
100%
100%
Token security section
100%
100%
MFA section
100%
100%
Account security section
87%
100%
TOTP secret exposure
100%
0%
MFA not enforced
100%
100%
Username enumeration
100%
100%
No account lockout
100%
100%
bcrypt or Argon2 recommendation
100%
100%
MFA enforcement recommendation
100%
100%
Hybrid session and JWT authentication analysis
Password security section
100%
100%
Session management section
100%
100%
Token security section
100%
100%
MFA section
100%
100%
Account security section
12%
37%
JWT signing algorithm
70%
50%
JWT expiration finding
100%
100%
JWT audience/issuer finding
100%
100%
Session HttpOnly finding
100%
100%
Session Secure finding
100%
100%
Refresh token recommendation
100%
100%
Legacy authentication security assessment
Password security section
100%
100%
Session management section
100%
100%
Token security section
100%
100%
MFA section
100%
100%
Account security section
100%
100%
bcrypt or Argon2 recommendation
100%
100%
Per-user salt recommendation
100%
100%
Short-lived token recommendation
100%
100%
Refresh token rotation
100%
100%
MFA recommendation
100%
100%
OAuth and API key partner authentication validation
Password security section
0%
0%
Session management section
0%
0%
Token security section
40%
40%
MFA section
0%
0%
Account security section
0%
0%
OAuth state parameter
100%
100%
PKCE requirement
100%
100%
Implicit flow deprecation
100%
100%
Redirect URI wildcard finding
100%
100%
API key URL exposure
100%
100%
API key plaintext storage
100%
100%
API key rotation
100%
100%
API key scope restriction
100%
100%
13d35b8
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.