Broken Authentication Testing
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides templates for using Hydra to perform automated brute-force attacks against login forms and outlines procedures for using Burp Suite for credential stuffing and multi-factor authentication bypass attempts.
- [DYNAMIC_EXECUTION]: Includes a Python code snippet that uses the
requestslibrary to programmatically fetch and analyze session tokens from remote web servers. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process data from external authentication endpoints, which constitutes an untrusted data surface that could be exploited via indirect prompt injection. * Ingestion points: Target web application responses from endpoints such as
/login,/signin, and/api/auth/*(SKILL.md). * Boundary markers: Absent; no delimiters or security instructions are provided to the agent regarding the handling of external server content. * Capability inventory: The skill utilizes network-active tools includinghydra,Burp Suite, and the Pythonrequestslibrary (SKILL.md). * Sanitization: Absent; the documentation lacks instructions for validating or sanitizing responses received from tested applications.
Audit Metadata