{"slug":"authentication-testing","title":"authentication-testing","summary":"Use this skill when you need evidence-bounded authentication-testing analysis and validation preparation; triggers include 身份认证测试 and authentication-testing.","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-09-24T14:54:57.78056Z","repo":{"url":"https://github.com/naodeng/awesome-qa-skills","stars":230,"forks":31,"license":null,"updatedAt":"2026-09-22T13:51:34Z"},"bodyHtml":"<hr>\n<h2>name: authentication-testing\ndescription: Use this skill when you need evidence-bounded authentication-testing analysis and validation preparation; triggers include 身份认证测试 and authentication-testing.</h2>\n<h1>Authentication Testing</h1>\n<h2>When to Use</h2>\n<ul>\n<li>Use this Skill when the work needs evidence-bounded analysis of identity credentials, authentication flows, failure paths, and lifecycle.</li>\n<li>Use it when input is incomplete but a reviewable draft with assumptions and gaps is still useful.</li>\n<li>Use it when static security evidence must remain separate from planned validation and completed execution.</li>\n</ul>\n<h2>Output Format Options</h2>\n<ul>\n<li>Default to Markdown organized by security risk, evidence, and priority.</li>\n<li>If the user asks for a table, CSV, JSON, or ticket format, preserve the same finding fields and evidence states.</li>\n<li>Confirm the schema, enum values, and required fields before feeding the output to automation.</li>\n</ul>\n<h2>How to Use</h2>\n<ol>\n<li>Read prompts/authentication-testing.md and follow its input audit, coverage checklist, and output contract.</li>\n<li>Extract scope, environment, version, roles, data, dependencies, constraints, and available evidence.</li>\n<li>Model identity credentials, authentication flows, failure paths, and lifecycle with reviewable scenarios, separating known facts, inferences, and candidate validation.</li>\n<li>Record impact, priority, owner role, close condition, and validation method for each item.</li>\n<li>With incomplete input, deliver a bounded draft; do not turn a risk assumption into a confirmed vulnerability or security pass.</li>\n</ol>\n<h2>Reference Files</h2>\n<ul>\n<li>Read prompts/authentication-testing.md for every invocation.</li>\n<li>Read evals/eval.yaml and matching evals/cases/ when evaluating the Skill.</li>\n<li>Read references/, examples/, scripts/, or output-formats.md only when the directory exists and the task needs it.</li>\n</ul>\n<h2>Core Constraints</h2>\n<ul>\n<li>Analyze only identity credentials, authentication flows, failure paths, and lifecycle; do not log in, call real APIs, or read credentials.</li>\n<li>Do not invent vulnerabilities, exploit success, remediation completion, scan coverage, or security-pass claims.</li>\n<li>Mark unsupported evidence as pending, blocked, or unassessed and provide an isolated validation method.</li>\n<li>Leave risk acceptance, exception authorization, and release judgment to a Human.</li>\n</ul>\n<h2>Delivery Self-Check</h2>\n<ul>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Complete the known, missing, conflicting, stale, out_of_scope, and assumptions audit.</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Cover the authentication, triggers, expected concerns, and evidence state.</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Separate facts, inferences, recommendations, gaps, and Human decisions.</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Do not turn static findings or a dry-run into a real exploit, absence-of-vulnerability, or release-approval claim.</li>\n</ul>\n<h2>Common Pitfalls</h2>\n<ul>\n<li>Treating broad security review or API contract checking as a complete substitute for Authentication Testing.</li>\n<li>Listing attack names without applicability, evidence, expected results, or close conditions.</li>\n<li>Declaring a system secure with incomplete input, or reading real credentials for completeness.</li>\n</ul>\n<h2>Best Practices</h2>\n<ul>\n<li>Start with high-impact, hard-to-detect, permission-sensitive, or data-sensitive paths.</li>\n<li>Use redacted material, least privilege, isolated environments, and reversible validation suggestions.</li>\n<li>Make each security conclusion reviewable by another engineer from its source and boundary.</li>\n</ul>\n","files":[{"path":"agents/openai.yaml","sizeBytes":332,"isText":true},{"path":"evals/cases/basic-success.yaml","sizeBytes":1367,"isText":true},{"path":"evals/cases/edge-incomplete-input.yaml","sizeBytes":803,"isText":true},{"path":"evals/cases/edge-scope-boundary.yaml","sizeBytes":890,"isText":true},{"path":"evals/eval.yaml","sizeBytes":441,"isText":true},{"path":"evals/local-rules.json","sizeBytes":141,"isText":true},{"path":"evals/trigger-prompts.csv","sizeBytes":445,"isText":false},{"path":"prompts/authentication-testing.md","sizeBytes":3966,"isText":true},{"path":"SKILL.md","sizeBytes":3319,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"clean","suspicious":0,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-09-24T14:57:14.28324Z","sha256":"1AA7FDC76923C782D2286B48DBB1D6B84FFFE37DFDA636334BC66935726FD2F8","sizeBytes":6363},"review":null,"source":{"repositoryUrl":"https://github.com/naodeng/awesome-qa-skills","path":"skills/en/testing-types/authentication-testing","license":null,"commit":"c44b8922085e01bafc804d1ffa3f21d4cec1d1c5","subtreeSha":"F578CD996E2315765125453A3EADC5F39153AA5C4A1D598CC87FE68C1DB8ABE4","lastSyncedAt":"2026-09-24T14:54:50.849933Z"},"reviewedAt":"2026-09-24T15:05:18.467563Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/naodeng/awesome-qa-skills/tree/main/skills/en/testing-types/authentication-testing"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install naodeng-awesome-qa-skills@llmmart"},{"target":"git","command":"git clone https://github.com/naodeng/awesome-qa-skills.git"}]}