pentest-auth-bypassTest authentication and session management controls for bypass and account takeover scenarios.
Install via ClawdBot CLI:
clawdbot install 0x-professor/pentest-auth-bypassGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://github.com/vanhauser-thc/thc-hydraAudited Apr 16, 2026 · audit v1.0
Generated Mar 20, 2026
Test online banking portals for weak session management and MFA bypass to prevent account takeover. Simulate attacks like session fixation or credential stuffing to validate controls against unauthorized access to sensitive financial data.
Assess patient portals for vulnerabilities in authentication tokens or cookies that could allow unauthorized access to medical records. Focus on brute-force resistance and session integrity to comply with HIPAA security requirements.
Evaluate e-commerce platforms for flaws in login mechanisms, such as weak password policies or lack of rate limiting, that could lead to credential theft and fraud. Ensure session management prevents unauthorized purchases or data breaches.
Test VPN gateways for authentication bypass techniques, like default credentials or misconfigured MFA, to prevent unauthorized network access. Validate controls against brute-force attacks to secure remote work environments.
Assess government web applications for vulnerabilities in authentication flows that could allow privilege escalation or data leakage. Focus on session integrity and MFA enforcement to protect sensitive public information.
Offer subscription-based security testing services using this skill to continuously assess client authentication systems. Generate revenue through monthly or annual contracts, providing automated reports and compliance validation.
Use this skill in consulting engagements to help organizations meet regulatory standards like PCI DSS or GDPR by testing authentication controls. Charge per project or hourly rates for detailed findings and remediation guidance.
Integrate this skill into existing security platforms, such as vulnerability management tools, to enhance automated testing capabilities. Monetize through licensing fees or as an add-on feature for enterprise customers.
💬 Integration Tip
Ensure scope validation is configured to prevent out-of-target testing, and use the provided schemas for consistent reporting across skills.
Scored Apr 19, 2026
Self-hosted auth for TypeScript/Cloudflare Workers with social auth, 2FA, passkeys, organizations, RBAC, and 15+ plugins. Requires Drizzle ORM or Kysely for D1 (no direct adapter). Self-hosted alternative to Clerk/Auth.js. Use when: self-hosting auth on D1, building OAuth provider, multi-tenant SaaS, or troubleshooting D1 adapter errors, session caching, rate limits, Expo crashes, additionalFields bugs.
Clerk integration. Manage Users, Organizations. Use when the user wants to interact with Clerk data.
Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP outages), and component reference. Prevents 15 documented errors. Use when: API keys for users/orgs, Next.js 16 middleware filename, troubleshooting JWKS/CSRF/JWT/token-type-mismatch errors, webhook verification, user type inconsistencies, or testing with 424242 OTP.
Use when auditing Go code involving authentication flows, RBAC policies, Kubernetes admission webhooks, JWT/OAuth token validation, or privilege escalation i...
Manages consent with strict safety limits, prohibits profiling or coercion, limits crisis inference, and ensures autonomy without persistent tracking or pres...
Agent verification via ClawX OAuth system. Use when checking agent verification status, embedding verification widgets, or working with agent identity/trust tiers.