tag

authentication

26 indexed skills · max 10 per page

skills (26)

implementing-passwordless-authentication-with-fido2

mukul975/Anthropic-Cybersecurity-Skills · implementing-passwordless-authentication-with-fido2

0

Deploy FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators. Covers WebAuthn API integration, FIDO2 server configuration, passkey enrollment, biometric authentica

implementing-zero-knowledge-proof-for-authentication

mukul975/Anthropic-Cybersecurity-Skills · implementing-zero-knowledge-proof-for-authentication

0

Zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identificati

testing-mobile-api-authentication

mukul975/Anthropic-Cybersecurity-Skills · testing-mobile-api-authentication

0

Tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insecure token management, session fixation, privilege escalation, and IDOR vulnerabilities. Use when performing API security assessments against mobile app backends, testing JWT implementations, evaluating OAuth flows, or assessing session management. Activates for requests involving mobile API auth testing, token security assessment, OAuth mobile flow testing, or API authorization bypass.

testing-websocket-api-security

mukul975/Anthropic-Cybersecurity-Skills · testing-websocket-api-security

0

Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket messages, insufficient input validation, denial-of-service via message flooding, and information leakage through WebSocket frames. The tester intercepts WebSocket handshakes and messages using Burp Suite, crafts malicious payloads, and tests for authorization bypass on WebSocket channels. Activates for requests involving WebSocket security testing, WS penetration testing, CSWSH attack, or real-time API security assessment.

testing-api-authentication-weaknesses

mukul975/Anthropic-Cybersecurity-Skills · testing-api-authentication-weaknesses

0

Tests API authentication mechanisms for weaknesses including broken token validation, missing authentication on endpoints, weak password policies, credential stuffing susceptibility, token leakage in URLs or logs, and session management flaws. The tester evaluates JWT implementation, API key handling, OAuth flows, and session token entropy to identify authentication bypasses. Maps to OWASP API2:2023 Broken Authentication. Activates for requests involving API authentication testing, token validation assessment, credential security testing, or API auth bypass.

testing-jwt-token-security

mukul975/Anthropic-Cybersecurity-Skills · testing-jwt-token-security

0

Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.

exploiting-oauth-misconfiguration

mukul975/Anthropic-Cybersecurity-Skills · exploiting-oauth-misconfiguration

0

Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during security assessments.

implementing-saml-sso-with-okta

mukul975/Anthropic-Cybersecurity-Skills · implementing-saml-sso-with-okta

0

Implement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end configuration of SAML authentication flows, attribute mapping, certificate management, a

testing-oauth2-implementation-flaws

mukul975/Anthropic-Cybersecurity-Skills · testing-oauth2-implementation-flaws

0

Tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass. The tester evaluates the authorization server, client application, and token handling for common misconfigurations that enable account takeover or unauthorized access. Activates for requests involving OAuth security testing, OIDC vulnerability assessment, OAuth2 redirect bypass, or authorization code flow testing.

configuring-multi-factor-authentication-with-duo

mukul975/Anthropic-Cybersecurity-Skills · configuring-multi-factor-authentication-with-duo

0

Deploy Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points. This skill covers Duo integration methods, adaptive authentication policies, device trust

prevpage 1 / 3next