web-mfa-bypass
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides logic for manipulating authentication flows which constitutes an indirect prompt injection surface.
- Ingestion points: Authentication responses, status codes, and parameters like otp or code as specified in SKILL.md.
- Boundary markers: None are defined to distinguish between data and instructions during flow analysis.
- Capability inventory: The methodology involves using automated security tools for brute-forcing and traffic manipulation.
- Sanitization: No sanitization methods are specified for the authentication data being processed.
Audit Metadata