What problem does it solve? Security testers need a disciplined, evidence-gated method to assess SAML SSO implementations without touching production identity providers or fabricating attack artifacts. This Skill structures the modeling of metadata, signature coverage, audience/recipient checks, time windows, and account mapping inside authorized IdP/SP test tenants. ## Core Features & Use Cases - SAML Flow Modeling: Records EntityID, ACS endpoints, bindings, signing certificates, Audience, Recipient, InResponseTo, NotBefore/NotOnOrAfter, and NameID/role mappings from captured assertions. - Configuration Consistency Auditing: Verifies whether the SP requires response/assertion signatures and strictly validates issuer, audience, recipient, clock skew, and request correlation. - Evidence-Gated Oracles: Defines a valid finding as a self-owned test SP accepting a spec-noncompliant, repeatable assertion, while treating malformed XML, expired certificates, and IdP misconfiguration as non-findings. - Use Case: During an authorized enterprise SSO assessment, use this Skill to baseline the SP's validation behavior, test expected rejection paths, and document metadata hashes and assertion field summaries as evidence. ## Quick Start Ask the agent to model and audit the SAML SSO configuration of my authorized test IdP and SP tenant, checking signature requirements and audience/recipient validation.