oauth-oidc-misconfiguration

>-

INSTALLATION
npx skills add https://github.com/yaklang/hack-skills --skill oauth-oidc-misconfiguration
Run in your project or agent environment. Adjust flags if your CLI version differs.

SKILL.md

$27

Theme

What to Check

state handling

missing, static, predictable, or not bound to user session

redirect_uri validation

prefix match, open redirect chaining, path confusion, localhost leftovers

PKCE

missing for public clients, code verifier not enforced, downgraded flow

OIDC nonce

missing or not validated on ID token return

token audience and issuer

weak aud / iss checks, cross-client token reuse

account binding

callback binds attacker identity to victim session

scope handling

broader scopes granted than the user or client should receive

3. QUICK TRIAGE

  • Map the full flow: authorize, callback, token exchange, logout.
  • Replay callback flows with altered state, nonce, and redirect_uri.
  • Compare SPA, mobile, and web clients for weaker validation.
  • Check whether one provider account can be rebound to another local account.

4. RELATED ROUTES

BrowserAct

Let your agent run on any real-world website

Bypass CAPTCHA & anti-bot for free. Start local, scale to cloud.

Explore BrowserAct Skills →

Stop writing automation&scrapers

Install the CLI. Run your first Skill in 30 seconds. Scale when you're ready.

Start free
free · no credit card