Skip to main content
在 Manus 中运行任何 Skill
一键导入

auth-flaw-hunter

星标15
分支7
更新时间2026年6月28日 16:46

Tests authentication subsystems for username enumeration, weak / absent lockout, multi-stage bypass (skipping MFA / security-questions stage), JWT signature integrity (dispatching to jwt-hunter), alternative-channel weakness (web vs mobile vs API), default-credential probing, and cleartext credential transmission. Use when login / password-reset / MFA flows are in scope; after `web-recon-active` maps the auth surface; or when the orchestrator's phase-0 plan prioritizes authentication hardening. Produces findings with CWE-287 / CWE-307 / CWE-522 mapping and layered auth hardening. Defensive testing only, against assets listed in .claude/security-scope.yaml - service_affecting: true.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

文件资源管理器
2 个文件
SKILL.md
readonly