attacking-oauth-oidc
trilwu/secskillsAttack OAuth 2.0 and OpenID Connect flows — enumerate endpoints from the OIDC discovery document, break redirect_uri validation with path traversal,…
Scores out of 100 · grade B+
2026-08-21Works
40% of the score100/100
- Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score92/100
- no commits in the last 12 weeks
Adopted
20% of the score29/100
- 122 stars on the source repo.
Documented
15% of the score81/100
- 2,164 words with worked examples.
Install
npx skills add trilwu/secskills/attacking-oauth-oidcWhat it says it does
Attack OAuth 2.0 and OpenID Connect flows — enumerate endpoints from the OIDC discovery document, break redirect_uri validation with path traversal, open-redirect chaining, subdomain and regex weakness, and %2F/@ parser tricks, exploit missing state (callback CSRF) and absent or downgraded PKCE, steal codes and tokens via open redirectors and referer leakage, replay and inject authorization codes across clients, escalate scope and bypass consent, confuse access_token with id_token, and take over accounts through "Sign in with X" email trust and device-code consent phishing. Use when you see /authorize, /oauth/token, response_type, redirect_uri, client_id, code= or state= parameters, a "Sign in with Google/Microsoft/GitHub" button, or an OIDC discovery document at /.well-known/openid-configuration.
Also in trilwu/secskills
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| auditing-code-for-vulnerabilitiestrilwu/secskills | clean | Skill | 122 stars | 14 days ago | |
| securing-ai-systemstrilwu/secskills | clean | Skill | 122 stars | 14 days ago | |
| cracking-passwordstrilwu/secskills | clean | Skill | 122 stars | 14 days ago | |
| escalating-windows-privilegestrilwu/secskills | clean | Skill | 122 stars | 14 days ago | |
| establishing-persistencetrilwu/secskills | clean | Skill | 122 stars | 14 days ago | |
| exploiting-cloud-platformstrilwu/secskills | clean | Skill | 122 stars | 14 days ago |
Other writing & docs skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| docxanthropics/skills | No license | Writing & docs | 175,275 installs | today | |
| vercel-optimizevercel-labs/agent-skills | No license | Writing & docs | 54,920 installs | today | |
| writing-skillsobra/superpowers | clean | Writing & docs | 171,278 installs | 2 days ago | |
| algorithmic-artanthropics/skills | No license | Writing & docs | 75,255 installs | today | |
| update-docsvercel/next.js | clean | Writing & docs | 142k stars | today | |
| writing-plansobra/superpowers | clean | Writing & docs | 226,365 installs | 2 days ago |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=trilwu%2Fsecskills)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
