CtrlK
BlogDocsLog inGet started
Tessl Logo

broken-authentication

Identify and exploit authentication and session management vulnerabilities in web applications. Broken authentication consistently ranks in the OWASP Top 10 and can lead to account takeover, identity theft, and unauthorized access to sensitive systems.

34

Quality

30%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

Fix and improve this skill with Tessl

tessl review fix ./plugins/antigravity-awesome-skills/skills/broken-authentication/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

27%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill is comprehensive in coverage but severely bloated, explaining many concepts Claude already knows (cookie flags, authentication types, common passwords) and presenting checklists as code blocks. The 10-phase workflow provides reasonable structure but lacks validation checkpoints and feedback loops critical for security testing. The entire content is monolithic with no progressive disclosure or external references, making it a poor fit for the SKILL.md format.

Suggestions

Cut at least 50% of content by removing explanations of concepts Claude already knows (cookie flags, what JWT is, default credential lists, authentication types) and focus only on novel testing methodology and specific tool commands.

Split into multiple files: keep SKILL.md as a concise overview with phases listed briefly, then reference separate files like PAYLOADS.md, SESSION-TESTING.md, JWT-ATTACKS.md, and MFA-BYPASS.md for detailed procedures.

Replace pseudocode comment blocks (e.g., '# Test minimum length', '# Check timing differences') with actual executable commands or scripts that produce measurable output.

Add explicit validation checkpoints between phases, such as 'Verify authorization document covers this test type before proceeding' and 'Confirm rate limit threshold before launching brute force to avoid account lockout of production accounts.'

DimensionReasoningScore

Conciseness

Extremely verbose at 300+ lines. Explains concepts Claude already knows (HTTP protocol, what session cookies are, what JWT is, authentication types). The purpose section restates the description. Tables like 'Session Cookie Flags' explain basic concepts (HttpOnly, Secure, SameSite) that Claude knows well. Default credential lists and common password lists are widely known and waste tokens.

1 / 3

Actionability

Provides some concrete commands (Hydra syntax, HTTP requests, Python script) but much of the content is pseudocode-like comments rather than executable code. Many 'bash' blocks are actually checklists or prose disguised as code. The Python session analysis script is incomplete (collects tokens but analysis is only comments). Steps like 'Check if session changed' lack specific verification commands.

2 / 3

Workflow Clarity

The 10-phase workflow is clearly sequenced and covers the domain well. However, there are no validation checkpoints or feedback loops between phases. For security testing involving potentially destructive operations (brute force, credential stuffing), there's no verification that authorization is confirmed before proceeding, no checkpoint to validate scope, and no structured decision points for when to stop or escalate.

2 / 3

Progressive Disclosure

Monolithic wall of text with no references to external files and no bundle files. All content is inline including reference tables, payload lists, and examples that could easily be split into separate files (e.g., payloads.md, session-testing.md, jwt-attacks.md). The document is overwhelming as a single file with no navigation structure beyond sequential headings.

1 / 3

Total

6

/

12

Passed

Description

32%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description identifies a clear security domain (broken authentication) and mentions relevant concepts, but wastes its second sentence on educational context about OWASP rankings rather than providing explicit trigger guidance. It lacks a 'Use when...' clause and doesn't enumerate specific concrete techniques or testing actions, making it harder for Claude to confidently select this skill over other security-related skills.

Suggestions

Add an explicit 'Use when...' clause with trigger terms like 'login bypass', 'session hijacking', 'credential stuffing', 'JWT vulnerabilities', 'password reset flaws', or 'cookie security'.

Replace the OWASP educational sentence with specific concrete actions such as 'Tests for credential stuffing, session fixation, insecure token generation, weak password policies, and missing multi-factor authentication'.

Include common file/technology references users might mention, such as 'JWT', 'OAuth', 'SAML', 'session cookies', or 'authentication tokens' to improve trigger term coverage.

DimensionReasoningScore

Specificity

Names the domain (authentication/session management vulnerabilities) and general actions (identify and exploit), but doesn't list specific concrete actions like testing credential stuffing, session fixation, token analysis, or brute force attacks.

2 / 3

Completeness

Describes what the skill does (identify/exploit auth vulnerabilities) but has no explicit 'Use when...' clause or trigger guidance. The second sentence is informational context about OWASP rather than usage guidance, which should cap this at 2, but the 'when' is so absent it warrants a 1.

1 / 3

Trigger Term Quality

Includes relevant terms like 'authentication', 'session management', 'OWASP Top 10', 'account takeover', and 'broken authentication', but misses common user variations like 'login bypass', 'password reset', 'JWT', 'session hijacking', 'cookie security', or 'OAuth'.

2 / 3

Distinctiveness Conflict Risk

Focuses on authentication and session management specifically, which is somewhat distinct, but could overlap with general web security scanning, penetration testing, or other OWASP-related vulnerability skills.

2 / 3

Total

7

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.