{"slug":"transilienceai-authenticated-session-acquisition","source_name":"transilienceai/authenticated-session-acquisition","name":"Transilienceai/Authenticated Session Acquisition","description":"Acquire an authenticated session THROUGH MFA/OTP on an in-scope target and emit a reusable session artifact (Playwright storageState + Bearer) so executors can test the post-auth attack surface. Use when the highest-value authenticated classes (BOLA/IDOR/mass-assignment/injection on the real data APIs) are blocked because login is gated by SMS-OTP or TOTP MFA. Distinct from the authentication skill (which ATTACKS auth); this one legitimately authenticates and hands the session to the rest of the","version":1,"lift":{"pass_rate_delta_pts":18.18,"pass_rate_pct":54.5,"total_cases":22,"passed_cases":12,"tokens_delta_pct":31.2,"turns_delta_pct":0,"verdict":"mixed","benchmark_model":"gemini-3.6-flash","grading_method":"judged","completed_at":"2026-08-19T11:31:38.585338+00:00"},"skill_score":null,"benchmark_models":[{"model":"gemini-3.6-flash","headline":true,"delta_pts":18.18,"with_pass_pct":54.5,"without_pass_pct":36.4,"tokens_delta_pct":31.2,"turns_delta_pct":0,"total_cases":22,"cases_aggregated":21,"verdict":"mixed","never_hurt":false,"completed_at":"2026-08-19T11:31:38.585338+00:00","run_id":"e893eae7-e0dc-4a40-974d-5a691e8f1824","version_number":1,"is_latest_version":true,"gate":null}],"trust":{"skill_safety":"passed","safety_status":"clean","intent_verdict":"safe","content_status":"clean","indexable":true},"license":"MIT","install_count":0,"manifest_hash":"61ba268810d991eeefc5ed4da20961f76d399fb679a9c9772368c1596faf2387","raw_url":"https://app.decimal.ai/s/transilienceai-authenticated-session-acquisition/SKILL.md","scorecard_url":"https://app.decimal.ai/skills/transilienceai-authenticated-session-acquisition"}