bypassing-authentication-with-forced-browsing

mukul975/bypassing-authentication-with-forced-browsing · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Discover hidden directories, files, APIs, and administrative interfaces by enumerating URLs and testing authentication enforcement during authorized security assessments.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.2 KB
  • 📁scripts
  • ⚙️agent.py 6.7 KB
  • 📄LICENSE 11.0 KB

Related

  1. param-fuzz · shulkwisec
    Systematically fuzz web applications for hidden content and input validation vulnerabilities across directories, files, parameters, and authentication bypasses.
    21
    repo stars
  2. performing-directory-traversal-testing · mukul975 bundle
    Test web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on the server by manipulating file path parameters.
    24.6k
    repo stars
  3. cross-site-scripting-xss-complete-deep-dive · shulkwisec bundle
    Provides a complete deep-dive into Cross-Site Scripting (XSS) with exact payloads and bypass techniques for every PortSwigger lab variant, from apprentice to expert level.
    21
    repo stars
  4. csrf · shulkwisec
    Detect and exploit Cross-Site Request Forgery vulnerabilities by testing for missing or predictable CSRF tokens, absent SameSite cookie attributes, and JSON endpoints accepting text/plain Content-Type, with payloads and bypass techniques for security testing.
    21
    repo stars
  5. bola-idor · shulkwisec
    Detect and exploit Broken Object Level Authorization (BOLA) and Insecure Direct Object Reference (IDOR) vulnerabilities in APIs and web applications.
    21
    repo stars
  6. cors-misconfiguration-complete-deep-dive · shulkwisec bundle
    Provides a structured deep-dive into CORS misconfiguration vulnerabilities with exact payloads for every PortSwigger lab variant, including zero-day escalation techniques and blue-team detection guidance.
    21
    repo stars

Frequently asked questions

How do I install the bypassing-authentication-with-forced-browsing skill?

Run npx skillmds add mukul975/bypassing-authentication-with-forced-browsing in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the bypassing-authentication-with-forced-browsing skill do?

Discover hidden directories, files, APIs, and administrative interfaces by enumerating URLs and testing authentication enforcement during authorized security assessments. It is listed under Security, Penetration Testing on SkillMD.

Is bypassing-authentication-with-forced-browsing safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with bypassing-authentication-with-forced-browsing?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is bypassing-authentication-with-forced-browsing free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published bypassing-authentication-with-forced-browsing?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.