Authentication & Session Testing
When Invoked
The user runs /vapt auth <url> or this skill is triggered as part of Wave 3 during /vapt audit.
Prerequisites
Check for existing context:
- If
VAPT-SCAN.mdexists → use discovered login pages and auth endpoints - If
VAPT-WAVE2-CONTEXT.mdexists → use discovered services requiring auth - If no context → look for
/login,/signin,/auth,/api/auth,/wp-login.php
Phase 1: Authentication Mechanism Analysis
1.1 Identi
[Description truncada. Veja o README completo no GitHub.]