Agent Skillsyaklang/hack-skills › oauth-oidc-misconfiguration

oauth-oidc-misconfiguration

GitHub

针对 OAuth 2.0 和 OIDC 的误配置测试手册,涵盖重定向 URI、State/Nonce、PKCE、Token 绑定等安全检查点,用于识别身份认证流程中的安全漏洞。

skills/oauth-oidc-misconfiguration/SKILL.md yaklang/hack-skills

Trigger Scenarios

审查 OAuth/OIDC 登录集成 检查重定向 URI 处理逻辑 验证 PKCE 和 State 参数安全性

Install

npx skills add yaklang/hack-skills --skill oauth-oidc-misconfiguration -g -y
More Options

Use without installing

npx skills use yaklang/hack-skills@oauth-oidc-misconfiguration

指定 Agent (Claude Code)

npx skills add yaklang/hack-skills --skill oauth-oidc-misconfiguration -a claude-code -g -y

安装 repo 全部 skill

npx skills add yaklang/hack-skills --all -g -y

预览 repo 内 skill

npx skills add yaklang/hack-skills --list

SKILL.md

Frontmatter
{
    "name": "oauth-oidc-misconfiguration",
    "description": "OAuth and OIDC misconfiguration testing playbook. Use when reviewing redirect URI handling, state and nonce validation, PKCE, token audience, callback binding, and identity-provider trust flaws."
}

SKILL: OAuth and OIDC Misconfiguration — Redirects, PKCE, Scopes, and Token Binding

AI LOAD INSTRUCTION: Use this skill when the target uses OAuth 2.0 or OpenID Connect and you need a focused misconfiguration checklist: redirect URI validation, state and nonce handling, PKCE enforcement, token audience, and account binding mistakes.

1. WHEN TO LOAD THIS SKILL

Load when:

  • The app supports Login with Google, GitHub, Microsoft, Okta, or other IdPs
  • You see authorize, callback, redirect_uri, code, state, nonce, or code_challenge
  • Mobile or SPA clients rely on OAuth or OIDC flows

For token cryptography and JWT header abuse, also load:

2. HIGH-VALUE MISCONFIGURATION CHECKS

Theme What to Check
state handling missing, static, predictable, or not bound to user session
redirect_uri validation prefix match, open redirect chaining, path confusion, localhost leftovers
PKCE missing for public clients, code verifier not enforced, downgraded flow
OIDC nonce missing or not validated on ID token return
token audience and issuer weak aud / iss checks, cross-client token reuse
account binding callback binds attacker identity to victim session
scope handling broader scopes granted than the user or client should receive

3. QUICK TRIAGE

  1. Map the full flow: authorize, callback, token exchange, logout.
  2. Replay callback flows with altered state, nonce, and redirect_uri.
  3. Compare SPA, mobile, and web clients for weaker validation.
  4. Check whether one provider account can be rebound to another local account.

4. RELATED ROUTES

Version History

  • c9a4b9e Current 2026-07-06 00:24

Same Skill Collection

skills/401-403-bypass-techniques/SKILL.md
skills/active-directory-acl-abuse/SKILL.md
skills/active-directory-certificate-services/SKILL.md
skills/active-directory-kerberos-attacks/SKILL.md
skills/ai-ml-security/SKILL.md
skills/android-pentesting-tricks/SKILL.md
skills/anti-debugging-techniques/SKILL.md
skills/api-auth-and-jwt-abuse/SKILL.md
skills/api-authorization-and-bola/SKILL.md
skills/api-recon-and-docs/SKILL.md
skills/api-sec/SKILL.md
skills/arbitrary-write-to-rce/SKILL.md
skills/auth-sec/SKILL.md
skills/authbypass-authentication-flaws/SKILL.md
skills/binary-protection-bypass/SKILL.md
skills/browser-exploitation-v8/SKILL.md
skills/business-logic-vuln/SKILL.md
skills/business-logic-vulnerabilities/SKILL.md
skills/classical-cipher-analysis/SKILL.md
skills/clickjacking/SKILL.md
skills/cmdi-command-injection/SKILL.md
skills/code-obfuscation-deobfuscation/SKILL.md
skills/container-escape-techniques/SKILL.md
skills/cors-cross-origin-misconfiguration/SKILL.md
skills/crlf-injection/SKILL.md
skills/csp-bypass-advanced/SKILL.md
skills/csrf-cross-site-request-forgery/SKILL.md
skills/csv-formula-injection/SKILL.md
skills/dangling-markup-injection/SKILL.md
skills/defi-attack-patterns/SKILL.md
skills/dependency-confusion/SKILL.md
skills/deserialization-insecure/SKILL.md
skills/dns-rebinding-attacks/SKILL.md
skills/email-header-injection/SKILL.md
skills/expression-language-injection/SKILL.md
skills/file-access-vuln/SKILL.md
skills/format-string-exploitation/SKILL.md
skills/graphql-and-hidden-parameters/SKILL.md
skills/hack/SKILL.md
skills/hash-attack-techniques/SKILL.md
skills/heap-exploitation/SKILL.md
skills/http-host-header-attacks/SKILL.md
skills/http-parameter-pollution/SKILL.md
skills/http2-specific-attacks/SKILL.md
skills/idor-broken-object-authorization/SKILL.md
skills/injection-checking/SKILL.md
skills/insecure-source-code-management/SKILL.md
skills/ios-pentesting-tricks/SKILL.md
skills/jndi-injection/SKILL.md
skills/jwt-oauth-token-attacks/SKILL.md

Metadata

Files
0
Version
c9a4b9e
Hash
558df7a2
Indexed
2026-07-06 00:24

Главная - Вики-сайт
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-15 05:13
浙ICP备14020137号-1 $Гость$