mfa-on-mobile

Installation
SKILL.md

MFA on Mobile

Instructions

MFA on mobile covers both the app as the authenticator (TOTP / push) and the app as the user (consuming a second factor during login).

1. Factor Types

Factor Strength Notes
SMS OTP Weak SIM swap, SS7. Avoid unless regulation forces it.
Email OTP Weak–medium Inherits email account security.
TOTP (RFC 6238) Medium No phishing resistance on its own.
Push approval Medium Good UX; vulnerable to MFA fatigue.
FIDO2 / passkeys Strong Phishing-resistant. Prefer where available.

2. TOTP as an Authenticator App

Installs
3
GitHub Stars
2
First Seen
Aug 23, 2026
mfa-on-mobile — almasumdev/awesome-mobile-security-agent-skills