oauth-sso
Analyze OAuth/OIDC/SSO flows as identity-chain attack surfaces.
Instalar con Codex o Claude Copia este prompt, pégalo en Codex, Claude u otro asistente, y deja que revise la página de la skill y la instale por ti.
Menú
Analyze OAuth/OIDC/SSO flows as identity-chain attack surfaces.
Instalar con Codex o Claude Copia este prompt, pégalo en Codex, Claude u otro asistente, y deja que revise la página de la skill y la instale por ti.
Basado en la clasificación ocupacional SOC
Four-phase autonomous bug bounty orchestration. Phase 0 maps external assets with deterministic Python helpers, Phase 1 lets AI prioritize attack surfaces, Phase 2 gives AI autonomous attack control, and Phase 3 produces verifier-only reports.
Four-phase autonomous bug bounty workflow. Python handles deterministic collection and verifier support; AI owns prioritization, attack reasoning, and autonomous direction changes.
Report generation agent. Convert verifier-confirmed findings into a fixed evidence-based report without adding speculative impact.
Rank reconnaissance-derived attack surfaces and design evidence-driven tests without active exploitation.
Test ranked attack surfaces autonomously, preserve evidence, and turn new access into additional attack-chain hypotheses.
A compact routing skill for choosing vulnerability hypotheses; detailed payloads live in references, not here.
| name | oauth-sso |
| description | Analyze OAuth/OIDC/SSO flows as identity-chain attack surfaces. |
| metadata | {"tags":"oauth,oidc,sso,identity"} |
判断登录、授权、回调、token 交换和账号绑定流程是否能导致身份混淆、会话固定、越权登录或权限提升。
references/INDEX.md;候选资源:decision-trees.md