PluginBench
Skill
Pass
Audit score 90

oauth-oidc-misconfiguration

yaklang/hack-skills

OAuth and OIDC misconfiguration testing playbook for redirect URIs, state/nonce validation, PKCE, and token binding flaws.

What is oauth-oidc-misconfiguration?

Focused checklist for reviewing OAuth 2.0 and OpenID Connect implementations. Use when testing apps with social login, callback flows, or identity provider integrations to identify redirect URI validation gaps, state/nonce handling weaknesses, PKCE enforcement issues, and account binding vulnerabilities.

  • Check state parameter handling for missing, static, predictable, or session-unbound values
  • Validate redirect_uri processing for prefix matching, open redirect chaining, and path confusion
  • Verify PKCE enforcement for public clients and code verifier validation
  • Test OIDC nonce validation on ID token returns
  • Audit token audience and issuer claims for weak validation and cross-client reuse
  • Identify account binding flaws where attacker identity rebinds to victim session

How to install oauth-oidc-misconfiguration

npx skills add https://github.com/yaklang/hack-skills --skill oauth-oidc-misconfiguration
Claude Code
Cursor
Windsurf
Cline

How to use oauth-oidc-misconfiguration

  1. 1.Map the complete OAuth/OIDC flow including authorize, callback, token exchange, and logout endpoints
  2. 2.Replay callback requests with altered state, nonce, and redirect_uri values to test validation
  3. 3.Compare validation strength across different client types (SPA, mobile, web)
  4. 4.Test account binding by attempting to rebind one provider account to another local account
  5. 5.Verify PKCE implementation for public clients and code verifier enforcement
  6. 6.Audit token audience (aud) and issuer (iss) claims for weak validation

Use cases

Good for
  • Testing social login implementations (Google, GitHub, Microsoft, Okta) for misconfiguration
  • Auditing mobile and SPA OAuth flows for weaker validation compared to web clients
  • Replaying callback flows with altered state, nonce, and redirect_uri parameters
  • Checking whether one provider account can be rebound to another local account
  • Mapping full OAuth/OIDC flows to identify token audience and issuer validation gaps
Who it's for
  • Security researchers auditing OAuth/OIDC implementations
  • Penetration testers reviewing social login and identity provider integrations
  • Application security engineers validating redirect URI and token binding logic
  • Developers implementing OAuth 2.0 or OpenID Connect flows

oauth-oidc-misconfiguration FAQ

When should I load this skill?

Load when the target uses OAuth 2.0 or OpenID Connect with social login, or when you see authorize, callback, redirect_uri, code, state, nonce, or code_challenge parameters.

What is the most common OAuth misconfiguration?

Weak or missing state parameter validation, which allows attackers to bypass CSRF protections and hijack authorization flows.

How do I test redirect_uri validation?

Try prefix matching attacks, open redirect chaining, path confusion, and check for localhost or development URIs left in production.

What should I check for PKCE?

Verify that public clients (mobile, SPA) enforce PKCE, validate the code verifier, and don't allow downgraded flows without PKCE.

What related skills should I load?

Load jwt-oauth-token-attacks for token cryptography issues, saml-sso-assertion-attacks for enterprise SSO, and cors-cross-origin-misconfiguration for token exposure.

Full instructions (SKILL.md)

Source of truth, from yaklang/hack-skills.


name: oauth-oidc-misconfiguration description: >- OAuth and OIDC misconfiguration testing playbook. Use when reviewing redirect URI handling, state and nonce validation, PKCE, token audience, callback binding, and identity-provider trust flaws.

SKILL: OAuth and OIDC Misconfiguration — Redirects, PKCE, Scopes, and Token Binding

AI LOAD INSTRUCTION: Use this skill when the target uses OAuth 2.0 or OpenID Connect and you need a focused misconfiguration checklist: redirect URI validation, state and nonce handling, PKCE enforcement, token audience, and account binding mistakes.

1. WHEN TO LOAD THIS SKILL

Load when:

  • The app supports Login with Google, GitHub, Microsoft, Okta, or other IdPs
  • You see authorize, callback, redirect_uri, code, state, nonce, or code_challenge
  • Mobile or SPA clients rely on OAuth or OIDC flows

For token cryptography and JWT header abuse, also load:

  • jwt oauth token attacks

2. HIGH-VALUE MISCONFIGURATION CHECKS

ThemeWhat to Check
state handlingmissing, static, predictable, or not bound to user session
redirect_uri validationprefix match, open redirect chaining, path confusion, localhost leftovers
PKCEmissing for public clients, code verifier not enforced, downgraded flow
OIDC noncemissing or not validated on ID token return
token audience and issuerweak aud / iss checks, cross-client token reuse
account bindingcallback binds attacker identity to victim session
scope handlingbroader scopes granted than the user or client should receive

3. QUICK TRIAGE

  1. Map the full flow: authorize, callback, token exchange, logout.
  2. Replay callback flows with altered state, nonce, and redirect_uri.
  3. Compare SPA, mobile, and web clients for weaker validation.
  4. Check whether one provider account can be rebound to another local account.

4. RELATED ROUTES

  • CORS or cross-origin token exposure: cors cross origin misconfiguration
  • XML federation or enterprise SSO: saml sso assertion attacks
  • CSRF-heavy login or binding bugs: csrf cross site request forgery