Audit authentication and authorization patterns. Checks JWT, sessions, OAuth2, PKCE implementations for security best practices and common vulnerabilities.
Pro scans all 3 files and shows the line behind each finding
Scanned 5/28/2026
npx -y skills add fusengine/agents --skill auth-audit --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Auth Audit?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/fusengine-auth-audit)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: auth-audit
description: Audit authentication and authorization patterns. Checks JWT, sessions, OAuth2, PKCE implementations for security best practices and common vulnerabilities.
argument-hint: "[--jwt] [--session] [--oauth]"
user-invocable: true
---
# Auth Audit Skill
## Overview
Comprehensive audit of authentication and authorization implementations.
## Audit Categories
| Category | Checks |
|----------|--------|
| JWT | Signing algo, expiration, refresh, storage |
| Sessions | Storage, expiry, regeneration, fixation |
| OAuth2 | PKCE, state param, redirect validation |
| Passwords | Hashing algo, strength rules, reset flow |
| MFA | Implementation, backup codes, recovery |
## Workflow
1. **Detect** auth implementation (JWT, sessions, OAuth)
2. **Scan** for known anti-patterns
3. **Verify** cryptographic choices
4. **Check** token/session lifecycle
5. **Audit** authorization logic (RBAC, ABAC)
## Common Vulnerabilities
- JWT signed with `none` algorithm
- JWT secret too short (< 256 bits)
- No token expiration or too long
- Refresh tokens stored in localStorage
- Session fixation after login
- Missing CSRF protection
- OAuth without PKCE for public clients
- Missing `state` parameter in OAuth flow
## References
- [Auth Patterns](references/auth-patterns.md)
- [Auth Checklist](references/templates/auth-checklist.md)
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!