pentest-auth-bypassTest authentication and session management controls for bypass and account takeover scenarios.
Install via ClawdBot CLI:
clawdbot install 0x-Professor/pentest-auth-bypassGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://github.com/vanhauser-thc/thc-hydraAudited Apr 16, 2026 · audit v1.0
Generated Mar 20, 2026
Test online banking portals for weak session management and MFA bypass to prevent account takeover. Simulate attacks like session fixation or credential stuffing to validate controls against unauthorized access to sensitive financial data.
Assess patient portals for vulnerabilities in authentication tokens or cookies that could allow unauthorized access to medical records. Focus on brute-force resistance and session integrity to comply with HIPAA security requirements.
Evaluate e-commerce platforms for flaws in login mechanisms, such as weak password policies or lack of rate limiting, that could lead to credential theft and fraud. Ensure session management prevents unauthorized purchases or data breaches.
Test VPN gateways for authentication bypass techniques, like default credentials or misconfigured MFA, to prevent unauthorized network access. Validate controls against brute-force attacks to secure remote work environments.
Assess government web applications for vulnerabilities in authentication flows that could allow privilege escalation or data leakage. Focus on session integrity and MFA enforcement to protect sensitive public information.
Offer subscription-based security testing services using this skill to continuously assess client authentication systems. Generate revenue through monthly or annual contracts, providing automated reports and compliance validation.
Use this skill in consulting engagements to help organizations meet regulatory standards like PCI DSS or GDPR by testing authentication controls. Charge per project or hourly rates for detailed findings and remediation guidance.
Integrate this skill into existing security platforms, such as vulnerability management tools, to enhance automated testing capabilities. Monetize through licensing fees or as an add-on feature for enterprise customers.
💬 Integration Tip
Ensure scope validation is configured to prevent out-of-target testing, and use the provided schemas for consistent reporting across skills.
Scored Apr 19, 2026
Use when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation, SQL injection prevention, XSS protection, or any security-related code review.
gws CLI: Shared patterns for authentication, global flags, and output formatting.
Set up Gmail API access via gog CLI with manual OAuth flow. Use when setting up Gmail integration, renewing expired OAuth tokens, or troubleshooting Gmail authentication on headless servers.
Automate OAuth login flows with user confirmation via Telegram. Supports 7 providers: Google, Apple, Microsoft, GitHub, Discord, WeChat, QQ. Features: - Auto-detect available OAuth options on login pages - Ask user to choose via Telegram when multiple options exist - Confirm before authorizing - Handle account selection and consent pages automatically
Self-hosted auth for TypeScript/Cloudflare Workers with social auth, 2FA, passkeys, organizations, RBAC, and 15+ plugins. Requires Drizzle ORM or Kysely for D1 (no direct adapter). Self-hosted alternative to Clerk/Auth.js. Use when: self-hosting auth on D1, building OAuth provider, multi-tenant SaaS, or troubleshooting D1 adapter errors, session caching, rate limits, Expo crashes, additionalFields bugs.
Zoho People API integration with managed OAuth. Manage employees, departments, designations, attendance, and leave. Use this skill when users want to read, create, update, or query HR data like employees, departments, designations, and forms in Zoho People. For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gateway). Requires network access and valid Maton API key.