hunt-mfa-bypass
Fail
Audited by Snyk on Aug 27, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (critical risk: 1.00). This skill contains explicit, actionable, and detailed instructions and tooling to bypass MFA/2FA and enable account takeover (brute-force OTP, token replay, response manipulation, race conditions, backup-code exfiltration), which is clearly malicious.
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill explicitly shows commands and code that embed session cookies/placeholders (e.g., YOUR_SESSION, PRE_MFA_SESSION) directly into curl/ffuf/Python requests, which requires inserting secret values verbatim into outputs/commands.
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata