instavm/security-skills

mitm-find-otp

Find OTP implementation vulnerabilities. Use when user asks about OTP security, verification bypass, SMS security, or two-factor authentication issues.

First seen Mar 23, 2026

Installation

$ npx skills add instavm/security-skills --skill mitm-find-otp

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from instavm/security-skills · top by installs.

npx skills add instavm/security-skills

Browse all from instavm/security-skills

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 84
Default branch main
Open issues 0
Status Active

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,797 B
  • docs SUMMARY.md 172 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 61 installs

SKILL.md

Find OTP Vulnerabilities

Analyze the mitmproxy dump (log.txt) for OTP issues for: $ARGUMENTS

Requires: log.txt in the current directory. If it's missing, capture traffic first:
```bash
mitmdump --set flow_detail=3 2>&1 | tee log.txt
```

Vulnerability Types

1. OTP in Response

  • OTP returned in API response body
  • OTP in page source/JavaScript
  • OTP in error messages
  • Should only be sent via SMS/email, never in API response

2. No Rate Limiting

  • Unlimited OTP generation requests
  • Unlimited verification attempts
  • Can brute force 4-6 digit OTP

3. OTP Bypass

  • Response manipulation bypasses OTP
  • Changing verified: false to verified: true
  • Empty OTP accepted
  • Old OTP still valid

4. Predictable OTP

  • Sequential OTPs
  • Timestamp-based OTPs
  • Same OTP for multiple requests

5. OTP Leakage

  • OTP in URL parameters (logged)
  • OTP visible in function names in source
  • OTP sent in GET request

Testing Approach

# Check for OTP in response
curl -X POST "https://target.com/api/send-otp" \
  -d "phone=1234567890" | grep -i otp

# Test rate limiting
for i in {1..20}; do
  curl -X POST "https://target.com/api/verify-otp" \
    -d "phone=1234567890&otp=$i"
done

# Test with empty/invalid OTP
curl -X POST "https://target.com/api/verify-otp" \
  -d "phone=1234567890&otp="

Output Format

For each finding:

  • Endpoint: OTP send/verify URL
  • Issue: Type of vulnerability
  • Evidence: What was observed
  • Exploit: Steps to reproduce
  • Impact: Account takeover risk
  • Fix: Server-side validation, rate limiting