Skip to main content
Run any Skill in Manus
with one click

oauth-oidc-hunter

Stars15
Forks7
UpdatedJune 28, 2026 at 16:46

Tests OAuth 2.0 / OpenID Connect flows for redirect-URI validation weaknesses (exact match vs substring / subdomain confusion), open-redirect chaining, missing / predictable `state` (CSRF on account linking), authorization-code reuse, implicit-flow fallback, `response_type` tampering, and redirect-URI parameter pollution. Use when the target integrates 'Login with X' SSO, has OAuth-protected APIs, exposes `/.well-known/openid-configuration`, or uses bearer tokens. Produces findings with CWE-601 / CWE-352 / CWE-346 mapping, complete flow evidence (authorize → callback → token exchange), and PKCE / strict-match remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
2 files
SKILL.md
readonly