Agent Skills: authenticated-session-acquisition

Acquire an authenticated session THROUGH MFA/OTP on an in-scope target and emit a reusable session artifact (Playwright storageState + Bearer) so executors can test the post-auth attack surface. Use when the highest-value authenticated classes (BOLA/IDOR/mass-assignment/injection on the real data APIs) are blocked because login is gated by SMS-OTP or TOTP MFA. Distinct from the authentication skill (which ATTACKS auth); this one legitimately authenticates and hands the session to the rest of the engagement.

UncategorizedID: transilienceai/communitytools/authenticated-session-acquisition

Install this agent skill to your local

pnpm dlx add-skill https://github.com/transilienceai/communitytools/authenticated-session-acquisition

Skill Files

Browse the full folder contents for authenticated-session-acquisition.

Download Skill

Loading file tree…

Select a file to preview its contents.