# Broken Authentication (agent skill)

> Broken Authentication is an agent skill (a SKILL.md file) from zebbern/claude-code-guide. It should be used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "perform credential stuffing tests", "evaluate password. It works with Claude Code, Codex and Cursor and has 4,648 GitHub stars across a repository of 4 listed skills.

This skill should be used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "perform credential stuffing tests", "evaluate password policies", "test for session fixation", or "identify authentication bypass flaws". It provides comprehensive techniques for identifying authentication and session management weaknesses in web applications. Identify and exploit authentication and session management vulnerabilities in web applications.

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/zebbern/claude-code-guide |
| Skill path | skills/broken-authentication/SKILL.md |
| Skill name | broken-authentication |
| GitHub stars | 4,648 |
| Installs on skills.sh | not listed |
| License | MIT |
| Skills in repo | 4 |
| Plugin marketplace | no |
| Official | no |
| Works with | Claude Code, Codex, Cursor |
| Category | Security |
| Last commit | Oct 7, 2026 |

## When it triggers

- used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "perform credential stuffing tests", "evaluate password policies", "test for session fixation", or "identify authentication b
- "test for broken authentication vulnerabilities"
- "assess session management security"
- "perform credential stuffing tests"
- "evaluate password policies"
- "test for session fixation"
- "identify authentication bypass flaws"

## Add this skill

### Claude Code

```sh
git clone --depth 1 https://github.com/zebbern/claude-code-guide.git
cp -r claude-code-guide/skills/broken-authentication ~/.claude/skills/broken-authentication   # personal, or .claude/skills in a project
```

In the Claude apps, zip the skill folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

### ChatGPT / Codex

```sh
git clone --depth 1 https://github.com/zebbern/claude-code-guide.git
cp -r claude-code-guide/skills/broken-authentication .agents/skills/broken-authentication   # repo; ~/.agents/skills for all projects
```

### Cursor

```sh
git clone --depth 1 https://github.com/zebbern/claude-code-guide.git
cp -r claude-code-guide/skills/broken-authentication .cursor/skills/broken-authentication   # project; ~/.cursor/skills for all projects
```

Sources (checked 2026-10-07): https://code.claude.com/docs/en/skills, https://support.claude.com/en/articles/12512180-using-skills-in-claude, https://learn.chatgpt.com/docs/build-skills, https://cursor.com/docs/context/skills

---

Canonical page: https://appsgit.com/skills/zebbern-broken-authentication
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
