CtrlK
BlogDocsLog inGet started
Tessl Logo

broken-authentication

This skill should be used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "perform credential stuffing tests", "evaluate password policies", "test for session fixation", or "identify authentication bypass flaws". It provides comprehensive techniques for identifying authentication and session management weaknesses in web applications.

56

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/broken-authentication/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a well-organized, largely actionable testing playbook with concrete commands, payload lists, and worked examples across ten clearly sequenced phases. Its main weaknesses are the monolithic inline structure with no reference files, the absence of validation/feedback checkpoints in batch workflows (brute force, credential stuffing), and padding that assumes Claude lacks knowledge it already has.

Suggestions

Move bulk material — credential payload lists, the vulnerability/risk tables, and the three worked examples — into references/ files (e.g. PAYLOADS.md, EXAMPLES.md) and keep SKILL.md as a phased overview with clearly signaled links.

Add explicit validation checkpoints to each phase, e.g. after brute-force testing confirm any successful login is a genuine bypass (not a redirect/captive page), and after session-fixation testing re-verify the pre/post-login token comparison from multiple accounts to rule out false positives.

Cut the motivational OWASP paragraph and the 'Required Knowledge' list (HTTP protocol, cookie handling) — Claude already knows these — and complete the session-token Python snippet so entropy/sequential-pattern analysis is executable rather than comment-only.

DimensionReasoningScore

Conciseness

Most of the body is operational (commands, header lists, payload tables), but it includes unnecessary material Claude already knows — the motivational OWASP Top 10 paragraph ('Broken authentication consistently ranks in the OWASP Top 10 and can lead to account takeover...') and the 'Required Knowledge' list ('HTTP protocol and session mechanisms', 'Cookie and token handling') — fitting the 'mostly efficient but includes some unnecessary explanation' anchor.

3 / 5

Actionability

The guidance is mostly executable: a copy-paste-ready hydra command, step-by-step Burp Intruder workflows, exact bypass headers (X-Forwarded-For etc.), concrete default-credential payloads, and worked exploit examples. Minor gaps keep it below the top anchor: the session-token Python snippet collects tokens but leaves entropy/pattern analysis as comments, and Phase 2's password-policy testing is a comment checklist rather than commands.

4 / 5

Workflow Clarity

The ten phases give a clear, coherent sequence, but validation checkpoints are absent or implicit — there is no verify-findings/confirm-false-positive step in any phase, and no feedback loops. Because brute force and credential stuffing are batch operations, the rubric's cap of 3 for missing validation in batch workflows applies.

3 / 5

Progressive Disclosure

The single 477-line SKILL.md is well-sectioned with headers, a quick reference, examples, and a troubleshooting table, so it is navigable — but there are no bundle files at all, and content that clearly belongs in separate references (credential payload lists, the vulnerability-type table, worked examples) is fully inlined, matching the 'some structure but content that should be separate is inline' anchor.

3 / 5

Total

13

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid description with an explicit, well-phrased trigger set that clearly answers when to use the skill. Its main weakness is the capability half, which relies on generic phrasing ('comprehensive techniques') instead of naming concrete capabilities, and a few natural trigger synonyms (MFA, login, password reset) are absent.

Suggestions

Replace the generic capability clause ('provides comprehensive techniques for identifying...') with 3-4 concrete capabilities, e.g. 'Test password policies, brute-force login endpoints, analyze session token entropy, and attempt MFA/password-reset bypasses'.

Add missing natural trigger variations users would say, such as 'test MFA/OTP security', 'audit login security', or 'check password reset flows'.

DimensionReasoningScore

Specificity

The domain is named and the trigger phrases cite concrete testing tasks ('test for session fixation', 'perform credential stuffing tests'), but the capability statement itself is one generic action — 'provides comprehensive techniques for identifying authentication and session management weaknesses' — with no enumerated concrete capabilities, matching the anchor for naming a domain with only 1-2 non-comprehensive actions.

3 / 5

Completeness

Both 'what' and 'when' are explicitly present, and the 'when' is unusually strong with six quoted trigger phrases, but the 'what' half is generic ('comprehensive techniques... weaknesses') rather than the concrete capability list of the top anchor.

4 / 5

Trigger Term Quality

Good keyword coverage with natural phrases users would actually say ('test for broken authentication vulnerabilities', 'evaluate password policies', 'identify authentication bypass flaws'), but common variations like 'MFA testing', 'login security', or 'password reset testing' are missing, placing it just below the comprehensive anchor.

4 / 5

Distinctiveness Conflict Risk

It carves out a clear niche (broken authentication) with distinct triggers, but 'evaluate password policies' and session/MFA scope could overlap closely related security-testing skills, giving minor overlap risk rather than minimal.

4 / 5

Total

15

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.