Broken Authentication Testing
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides command-line templates for security testing tools such as Hydra and Burp Suite. These are intended for authorized testing of authentication endpoints (e.g., brute-forcing credentials, testing rate limiting).
- [EXTERNAL_DOWNLOADS]: The skill mentions the use of common security wordlists like 'rockyou.txt', which is a standard resource in penetration testing environments.
- [DYNAMIC_EXECUTION]: Phase 6 includes a Python script template that uses the
requestsandhashliblibraries to collect and analyze session tokens for entropy and patterns. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze responses from external web applications (Phase 3 and Phase 9). This introduces a surface where untrusted data from a target server could potentially influence the agent's behavior, although no specific automated parsing of complex untrusted content is present.
- Ingestion points: Server responses from login, registration, and password reset endpoints (SKILL.md Phase 1, 3, 9).
- Boundary markers: None provided in the instruction templates.
- Capability inventory: Network requests via Python
requestsand tool execution via Hydra. - Sanitization: The skill focuses on manual analysis and standard tool output interpretation; explicit data sanitization instructions for the agent are not defined.
Audit Metadata