← Tahr SecurityCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Tahr Security
Snapshot Sep 30, 2026 · 23:16 UTC · version 0.3.3
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "tahr-test-authentication",
"description": "Review and safely test web authentication and session boundaries across login, registration, password reset, magic links, MFA or OTP, OAuth/OIDC, SAML, passkeys, tokens, cookies, logout, and recovery. Use for authentication code review, pre-release auth testing, account-takeover analysis, session-management review, SSO integration review, or validating an existing security assessment.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 251
},
{
"relative_path": "references/auth-matrix.md",
"size_in_bytes": 2773
},
{
"relative_path": "references/auth-proof-gates.md",
"size_in_bytes": 2612
}
],
"skill_md_contents": "---\nname: tahr-test-authentication\ndescription: Review and safely test web authentication and session boundaries across login, registration, password reset, magic links, MFA or OTP, OAuth/OIDC, SAML, passkeys, tokens, cookies, logout, and recovery. Use for authentication code review, pre-release auth testing, account-takeover analysis, session-management review, SSO integration review, or validating an existing security assessment.\n---\n\n# Test Authentication\n\nFind identity-boundary failures, not merely unusual responses. Treat auth material as untrusted until it proves the intended identity and transport.\n\n## Establish safe scope\n\n1. Identify source roots, runtime origins, supported authentication methods, supplied identities, and expected account lifecycle.\n2. Do not send runtime requests unless the user supplied or authorized the target. Use source-only analysis otherwise.\n3. Treat all supplied accounts as protected unless explicitly labeled disposable. Do not lock, reset, disable, delete, re-role, enroll or remove MFA/passkeys, rotate credentials, or invalidate all sessions on protected accounts.\n4. Use invalid identifiers for low-volume response-shape checks and disposable accounts for lockout, reset completion, password changes, MFA mutation, code replay, and takeover proof.\n5. Stop runtime testing on lockout text, CAPTCHA, rate limiting, disabled-account state, unexpected notification delivery, or unclear side effects.\n\n## Prove identity truth first\n\nFor each supplied identity:\n\n- observe the rendered login flow before submitting credentials;\n- classify password, split-step, OTP, MFA, magic-link, OAuth/OIDC/SAML, passkey, browser-bound, and custom stages;\n- identify hidden state, nonce, CSRF, tenant, organization, provider, or login-method choices;\n- validate success against an authenticated-only or identity-confirming endpoint;\n- record the observed user, role, tenant, auth mode, and whether cookies/tokens are portable or browser-bound.\n\nDo not equate a cookie, token, callback URL, HTTP 200, account picker, application shell, or pending MFA page with successful authentication. A failed role-specific login is a coverage blocker, not target access denial.\n\n## Model the lifecycle\n\nTrace these state transitions when present:\n\n`registration/invite -> verification -> login -> step-up/MFA -> session refresh -> logout/revocation`\n\n`forgot-password -> delivery -> token/code validation -> password change -> prior-session behavior`\n\n`OAuth/SAML/passkey initiation -> provider/authenticator -> callback/completion -> application session`\n\nRecord every endpoint, browser action, actor, token class, binding, one-time expectation, expiry, and alternate/mobile/legacy channel. Derive endpoints from source, specifications, JavaScript, and observed traffic before using fallback names.\n\n## Execute the abuse matrix\n\nRead [auth-matrix.md](references/auth-matrix.md). Prioritize tests that cross an identity boundary:\n\n- valid-disposable versus invalid account enumeration controls;\n- rate limiting and weaker alternate endpoints;\n- pre-auth, post-password, post-MFA, and fully authenticated stage skipping;\n- token/code replay, wrong-account binding, stale-token reuse, and parallel requests;\n- recovery, factor, password, email, and security-setting changes without reauthentication;\n- session fixation, logout/timeout invalidation, CSRF, cookie scope, and refresh rotation;\n- OAuth redirect/state/nonce/PKCE/code/client/scope binding;\n- credentials or reusable secrets in URLs, responses, logs, JavaScript, caches, or browser storage.\n\nChange one dimension at a time and pair every abuse attempt with a valid control. Refresh or re-establish the exact identity after an intentionally invalidating test before interpreting later responses.\n\n## Apply proof gates\n\nRead [auth-proof-gates.md](references/auth-proof-gates.md). Keep endpoint discovery, header observations, raw tokens, configuration smells, status codes, timing, and script labels in a candidate ledger until the class-specific proof gate passes.\n\nFor every confirmed issue, preserve:\n\n- exact flow stage, endpoint/action, and actor/session context;\n- baseline and manipulated request or browser action;\n- token/cookie class and state using redacted fingerprints;\n- authenticated-only data/action, wrong-account binding, replay, persistent state change, or other concrete impact;\n- safe, faithful reproduction steps and cleanup or restoration status.\n\nNever persist raw passwords, cookies, bearer/refresh tokens, authorization codes, reset/magic links, OTPs, SAML assertions, passkey material, secrets, or PII.\n\n## Report coverage honestly\n\nSeparate `confirmed`, `candidate`, `not_reproduced`, `blocked_for_safety`, and `not_applicable`. List every untested lifecycle stage, missing disposable identity, browser-bound limitation, unavailable delivery channel, stale session, or provider blocker. Do not turn incomplete auth coverage into “no issue found.”\n"
}SHA-256: fbe935afa45b6dbb2398fff687c3c7accd583b14c7954418dee5082daf554b51