hunt-mfa-bypass

Fail

Audited by Snyk on Aug 27, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (critical risk: 1.00). This skill contains explicit, actionable, and detailed instructions and tooling to bypass MFA/2FA and enable account takeover (brute-force OTP, token replay, response manipulation, race conditions, backup-code exfiltration), which is clearly malicious.

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill explicitly shows commands and code that embed session cookies/placeholders (e.g., YOUR_SESSION, PRE_MFA_SESSION) directly into curl/ffuf/Python requests, which requires inserting secret values verbatim into outputs/commands.

Issues (2)

E004
CRITICAL

Prompt injection detected in skill instructions.

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 27, 2026, 05:32 AM
Issues
2
Security Audit — snyk — hunt-mfa-bypass