Skip to content
Security
Skill

/saml-sso-assertion-attacks

SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictions, ACS handling, XML trust boundaries, and enterprise SSO flaws.

From plugin
hack-skills
1.6k102 skills
Install
$ npx -y skills add yaklang/hack-skills --skill saml-sso-assertion-attacks --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/saml-sso-assertion-attacks

Context preview

The summary Claude sees to decide when to auto-load this skill.

SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictions, ACS handling, XML trust boundaries, and enterprise SSO flaws.

SKILL.md

saml-sso-assertion-attacks.SKILL.md
name: saml-sso-assertion-attacks
description: >-
  SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictions, ACS handling, XML trust boundaries, and enterprise SSO flaws.

SKILL: SAML SSO and Assertion Attacks — Signature Validation, Binding, and Trust Confusion

> **AI LOAD INSTRUCTION**: Use this skill when the target uses SAML-based SSO and you need to validate assertion trust: signature coverage, audience and recipient checks, ACS handling, XML parsing weaknesses, and IdP/SP confusion.

1. WHEN TO LOAD THIS SKILL

Load when:

  • Enterprise SSO uses SAML requests or responses
  • You see `SAMLRequest`, `SAMLResponse`, XML assertions, or ACS endpoints
  • Login flows involve an external IdP and browser POST/redirect binding

2. HIGH-VALUE MISCONFIGURATION CHECKS

| Theme | What to Check | |---|---| | signature validation | unsigned assertion accepted, wrong node signed, signature wrapping | | audience and recipient | weak `Audience`, `Recipient`, `Destination`, or ACS validation | | issuer trust | wrong IdP accepted or multi-tenant issuer confusion | | replay and freshness | missing `InResponseTo`, weak `NotBefore` / `NotOnOrAfter` enforcement | | account mapping | email-only binding, case folding, unverified attributes | | XML parser behavior | XXE-like parser issues or unsafe transforms around SAML documents |

3. QUICK TRIAGE

1. Capture one full login round trip. 2. Inspect which XML nodes are signed and which attributes drive account binding. 3. Compare SP-initiated and IdP-initiated flows. 4. Test replay, altered attributes, and assertion placement confusion.

4. RELATED ROUTES

  • XML parser attack depth: [xxe xml external entity](../xxe-xml-external-entity/SKILL.md)
  • OAuth or OIDC SSO alternatives: [oauth oidc misconfiguration](../oauth-oidc-misconfiguration/SKILL.md)
  • Auth boundary issues after SSO: [authbypass authentication flaws](../authbypass-authentication-flaws/SKILL.md)
Read more
Ships withhack-skills

Master Entry → Category Entries → Deep Topic Skills One master entry, six category entries, and 101 deep topic skills across 14 security domains.

Get the whole plugin

Other skills on hack-skills.