401-403-bypass-techniq…
401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP…
OAuth and OIDC misconfiguration testing playbook. Use when reviewing redirect URI handling, state and nonce validation, PKCE, token audience, callback binding, and identity-provider trust flaws.
$ npx -y skills add yaklang/hack-skills --skill oauth-oidc-misconfiguration --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/oauth-oidc-misconfigurationContext preview
The summary Claude sees to decide when to auto-load this skill.
OAuth and OIDC misconfiguration testing playbook. Use when reviewing redirect URI handling, state and nonce validation, PKCE, token audience, callback binding, and identity-provider trust flaws.
name: oauth-oidc-misconfiguration description: >- OAuth and OIDC misconfiguration testing playbook. Use when reviewing redirect URI handling, state and nonce validation, PKCE, token audience, callback binding, and identity-provider trust flaws.
> **AI LOAD INSTRUCTION**: Use this skill when the target uses OAuth 2.0 or OpenID Connect and you need a focused misconfiguration checklist: redirect URI validation, state and nonce handling, PKCE enforcement, token audience, and account binding mistakes.
Load when:
For token cryptography and JWT header abuse, also load:
| Theme | What to Check | |---|---| | `state` handling | missing, static, predictable, or not bound to user session | | `redirect_uri` validation | prefix match, open redirect chaining, path confusion, localhost leftovers | | PKCE | missing for public clients, code verifier not enforced, downgraded flow | | OIDC `nonce` | missing or not validated on ID token return | | token audience and issuer | weak `aud` / `iss` checks, cross-client token reuse | | account binding | callback binds attacker identity to victim session | | scope handling | broader scopes granted than the user or client should receive |
1. Map the full flow: authorize, callback, token exchange, logout. 2. Replay callback flows with altered `state`, `nonce`, and `redirect_uri`. 3. Compare SPA, mobile, and web clients for weaker validation. 4. Check whether one provider account can be rebound to another local account.
Master Entry → Category Entries → Deep Topic Skills One master entry, six category entries, and 102 deep topic skills across 14 security domains.
Repo: yaklang/hack-skills
401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP…
Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS…
AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to…
Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets,…
AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing,…
Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent…