offensive-oauth
OAuth 2.0 attack checklist: authorization code interception, redirect_uri bypass, CSRF on OAuth flow, state parameter abuse, open redirector chaining, token leakage via Referer, PKCE bypass, and scope escalation. Use when testing OAuth implementations in web apps or bug bounty.
- Compatibility
- claude-code codex opencode
Pinned to revision 626b01ddea63, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/offensive-oauth/SKILL.md
- skills/offensive-oauth/LICENSE
- skills/offensive-oauth/README.md
- skills/offensive-oauth/agents/openai.yaml
Every link opens the file at its source, pinned to the revision this page describes.