What problem does it solve?
This skill addresses the complexity of identifying and exploiting high-value OAuth vulnerabilities, such as account takeover and session theft, which are often missed during standard security audits.
Core Features & Use Cases
- Comprehensive Methodology: Provides a structured, step-by-step approach to mapping OAuth flows, testing redirect_uri validation, and verifying state/nonce integrity.
- Payload Library: Includes a curated set of bypass payloads for common OAuth misconfigurations, including host confusion, path traversal, and parameter pollution.
- Use Case: Use this skill when auditing a web or mobile application that implements social login (Google, Facebook, Apple) to identify if an attacker can hijack user sessions or bypass authentication steps.
Quick Start
Use the hunt-oauth skill to audit the OAuth implementation on the target domain and identify potential account takeover vectors.