بنقرة واحدة
open-redirect-hunter
Tests URL-redirect parameters for arbitrary-destination redirects via simple external URLs, protocol-relative bypasses (`//attacker`), path-prefix tricks (`/https://attacker`), userinfo confusion (`target@attacker`), fragment/encoding bypasses, Referer-based redirects, and `javascript:` pseudo-protocol in href sinks. Use when parameters named `url`, `redirect`, `next`, `return`, `destination`, `goto`, `rUrl`, `cancelUrl` appear in the inventory; when login / logout / deep-link flows accept user-supplied redirect targets; or when chained with OAuth (`oauth-oidc-hunter`). Produces findings with CWE-601 mapping, redirect-chain evidence, and allowlist + user-warning remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.