Skip to content
Security
Skill

/oauth-oidc-misconfiguration

OAuth and OIDC misconfiguration testing playbook. Use when reviewing redirect URI handling, state and nonce validation, PKCE, token audience, callback binding, and identity-provider trust flaws.

From plugin
hack-skills
1.6k102 skills
Install
$ npx -y skills add yaklang/hack-skills --skill oauth-oidc-misconfiguration --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/oauth-oidc-misconfiguration

Context preview

The summary Claude sees to decide when to auto-load this skill.

OAuth and OIDC misconfiguration testing playbook. Use when reviewing redirect URI handling, state and nonce validation, PKCE, token audience, callback binding, and identity-provider trust flaws.

SKILL.md

oauth-oidc-misconfiguration.SKILL.md
name: oauth-oidc-misconfiguration
description: >-
  OAuth and OIDC misconfiguration testing playbook. Use when reviewing redirect URI handling, state and nonce validation, PKCE, token audience, callback binding, and identity-provider trust flaws.

SKILL: OAuth and OIDC Misconfiguration — Redirects, PKCE, Scopes, and Token Binding

> **AI LOAD INSTRUCTION**: Use this skill when the target uses OAuth 2.0 or OpenID Connect and you need a focused misconfiguration checklist: redirect URI validation, state and nonce handling, PKCE enforcement, token audience, and account binding mistakes.

1. WHEN TO LOAD THIS SKILL

Load when:

  • The app supports `Login with Google`, GitHub, Microsoft, Okta, or other IdPs
  • You see `authorize`, `callback`, `redirect_uri`, `code`, `state`, `nonce`, or `code_challenge`
  • Mobile or SPA clients rely on OAuth or OIDC flows

For token cryptography and JWT header abuse, also load:

  • [jwt oauth token attacks](../jwt-oauth-token-attacks/SKILL.md)

2. HIGH-VALUE MISCONFIGURATION CHECKS

| Theme | What to Check | |---|---| | `state` handling | missing, static, predictable, or not bound to user session | | `redirect_uri` validation | prefix match, open redirect chaining, path confusion, localhost leftovers | | PKCE | missing for public clients, code verifier not enforced, downgraded flow | | OIDC `nonce` | missing or not validated on ID token return | | token audience and issuer | weak `aud` / `iss` checks, cross-client token reuse | | account binding | callback binds attacker identity to victim session | | scope handling | broader scopes granted than the user or client should receive |

3. QUICK TRIAGE

1. Map the full flow: authorize, callback, token exchange, logout. 2. Replay callback flows with altered `state`, `nonce`, and `redirect_uri`. 3. Compare SPA, mobile, and web clients for weaker validation. 4. Check whether one provider account can be rebound to another local account.

4. RELATED ROUTES

  • CORS or cross-origin token exposure: [cors cross origin misconfiguration](../cors-cross-origin-misconfiguration/SKILL.md)
  • XML federation or enterprise SSO: [saml sso assertion attacks](../saml-sso-assertion-attacks/SKILL.md)
  • CSRF-heavy login or binding bugs: [csrf cross site request forgery](../csrf-cross-site-request-forgery/SKILL.md)
Read more
Ships withhack-skills

Master Entry → Category Entries → Deep Topic Skills One master entry, six category entries, and 101 deep topic skills across 14 security domains.

Get the whole plugin

Other skills on hack-skills.