Skip to main content
Run any Skill in Manus
with one click

open-redirect-hunter

Stars15
Forks7
UpdatedJune 28, 2026 at 16:46

Tests URL-redirect parameters for arbitrary-destination redirects via simple external URLs, protocol-relative bypasses (`//attacker`), path-prefix tricks (`/https://attacker`), userinfo confusion (`target@attacker`), fragment/encoding bypasses, Referer-based redirects, and `javascript:` pseudo-protocol in href sinks. Use when parameters named `url`, `redirect`, `next`, `return`, `destination`, `goto`, `rUrl`, `cancelUrl` appear in the inventory; when login / logout / deep-link flows accept user-supplied redirect targets; or when chained with OAuth (`oauth-oidc-hunter`). Produces findings with CWE-601 mapping, redirect-chain evidence, and allowlist + user-warning remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly