Broken Authentication Testing

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides templates for using Hydra to perform automated brute-force attacks against login forms and outlines procedures for using Burp Suite for credential stuffing and multi-factor authentication bypass attempts.
  • [DYNAMIC_EXECUTION]: Includes a Python code snippet that uses the requests library to programmatically fetch and analyze session tokens from remote web servers.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process data from external authentication endpoints, which constitutes an untrusted data surface that could be exploited via indirect prompt injection. * Ingestion points: Target web application responses from endpoints such as /login, /signin, and /api/auth/* (SKILL.md). * Boundary markers: Absent; no delimiters or security instructions are provided to the agent regarding the handling of external server content. * Capability inventory: The skill utilizes network-active tools including hydra, Burp Suite, and the Python requests library (SKILL.md). * Sanitization: Absent; the documentation lacks instructions for validating or sanitizing responses received from tested applications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — Broken Authentication Testing