Skip to main content
Exécutez n'importe quel Skill dans Manus
en un clic

oauth-oidc-hunter

Étoiles15
Forks7
Mis à jour28 juin 2026 à 16:46

Tests OAuth 2.0 / OpenID Connect flows for redirect-URI validation weaknesses (exact match vs substring / subdomain confusion), open-redirect chaining, missing / predictable `state` (CSRF on account linking), authorization-code reuse, implicit-flow fallback, `response_type` tampering, and redirect-URI parameter pollution. Use when the target integrates 'Login with X' SSO, has OAuth-protected APIs, exposes `/.well-known/openid-configuration`, or uses bearer tokens. Produces findings with CWE-601 / CWE-352 / CWE-346 mapping, complete flow evidence (authorize → callback → token exchange), and PKCE / strict-match remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.

Installation

Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.

Explorateur de fichiers
2 fichiers
SKILL.md
readonly