Skip to main content
在 Manus 中运行任何 Skill
一键导入

open-redirect-hunter

星标15
分支7
更新时间2026年6月28日 16:46

Tests URL-redirect parameters for arbitrary-destination redirects via simple external URLs, protocol-relative bypasses (`//attacker`), path-prefix tricks (`/https://attacker`), userinfo confusion (`target@attacker`), fragment/encoding bypasses, Referer-based redirects, and `javascript:` pseudo-protocol in href sinks. Use when parameters named `url`, `redirect`, `next`, `return`, `destination`, `goto`, `rUrl`, `cancelUrl` appear in the inventory; when login / logout / deep-link flows accept user-supplied redirect targets; or when chained with OAuth (`oauth-oidc-hunter`). Produces findings with CWE-601 mapping, redirect-chain evidence, and allowlist + user-warning remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

SKILL.md
readonly