CtrlK
BlogDocsLog inGet started
Tessl Logo

broken-authentication

Identify and exploit authentication and session management vulnerabilities in web applications. Broken authentication consistently ranks in the OWASP Top 10 and can lead to account takeover, identity theft, and unauthorized access to sensitive systems.

48

Quality

51%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/broken-authentication/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill is well-structured with a clear ten-phase methodology and a strong authorization gate, and it contains genuinely executable material (Hydra, bypass headers, JWT attack). However, much of the guidance is comment-style pseudocode rather than runnable commands, batch phases lack validation checkpoints, and nearly 500 lines of payloads and examples are inlined where a leaner overview plus reference files would serve better.

Suggestions

Convert comment-only blocks (password policy tests, enumeration checks, lockout checks) into concrete executable commands or request examples, mirroring the existing Hydra and JWT examples.

Add validation/feedback checkpoints to the batch phases — e.g., verify a test login succeeds before declaring a brute-force hit, and re-confirm scope before credential stuffing.

Move the payload lists, quick-reference tables, and worked examples into one-level-deep reference files (e.g. references/payloads.md, references/examples.md) and keep SKILL.md as a lean overview with clearly signaled links.

DimensionReasoningScore

Conciseness

The body is mostly commands, tables, and checklists rather than explanations of basics, but the Purpose section repeats the frontmatter description verbatim, many blocks are comment-only, and question-form bullet checklists ("After how many attempts?", "Requests per minute limit?") pad the token budget.

3 / 5

Actionability

Some guidance is fully executable (the Hydra command, rate-limit bypass headers, default credential list, JWT none-algorithm attack steps), but a large share of blocks are comment-only pseudocode such as "# Test minimum length (a, ab, abcdefgh)" and "# Compare responses for valid vs invalid usernames" rather than runnable commands.

3 / 5

Workflow Clarity

The ten phases are clearly sequenced and a mandatory confirmation gate precedes any active testing, but the brute-force and credential-stuffing phases are batch operations with no validation or feedback-loop checkpoints, which the rubric guidelines cap at 3.

3 / 5

Progressive Disclosure

Section structure and headers are good, but at roughly 485 lines the payload lists, quick-reference tables, and worked examples are all inlined in SKILL.md instead of being split into one-level-deep reference files; no bundle files exist to offload them.

3 / 5

Total

12

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description states a clear and reasonably specific capability in third person, but it omits any explicit "when to use" trigger guidance and leans on impact justification ("can lead to account takeover, identity theft") instead of enumerating the concrete testing techniques it actually covers. It would benefit most from a trigger clause and natural keywords.

Suggestions

Add an explicit trigger clause, e.g. "Use when testing web application login, session handling, MFA, or password reset functionality, or when the user mentions broken authentication or OWASP A07."

Replace the impact sentence with a compact enumeration of the concrete techniques covered (brute force, credential stuffing, session fixation, MFA bypass, password reset testing) to raise specificity and trigger-term coverage.

Include natural synonyms users would actually say ("login", "brute force", "MFA", "session tokens") so the skill triggers on real requests.

DimensionReasoningScore

Specificity

"Identify and exploit authentication and session management vulnerabilities in web applications" names the domain and two concrete actions, but the second sentence is impact framing rather than capability and the many sub-techniques covered in the body (brute force, MFA bypass, password reset) are not reflected.

3 / 5

Completeness

The "what" is clearly stated, but there is no "Use when..." clause or equivalent explicit trigger guidance, which the rubric caps at 3.

3 / 5

Trigger Term Quality

"authentication", "session management", "OWASP Top 10" are relevant keywords, but common natural phrases users would say when needing this skill ("login", "brute force", "MFA", "session tokens", "password reset") are missing.

3 / 5

Distinctiveness Conflict Risk

"authentication and session management vulnerabilities" carves out a fairly distinct niche, with only minor overlap risk against general web-pentest or OWASP-testing skills; it is not a 5 because the trigger surface is not distinct enough to rule out that overlap.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.