Use when tests OAuth 2.0 and OpenID Connect implementations for security
Scanned 9/8/2026
Install to Claude Code
npx -y skills add oyi77/1ai-skills --skill testing-oauth2-implementation-flaws --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Testing Oauth2 Implementation Flaws?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/oyi77-testing-oauth2-implementation-flaws)More formats (shields.io, HTML) on the badges page.
---
name: testing-oauth2-implementation-flaws
description: Use when tests OAuth 2.0 and OpenID Connect implementations for security
flaws including authorization code interception, redirect URI manipulation, CSRF
in OAuth flows, token leakage, scope escalation, and PKCE bypass. The tester evaluates
the authorization server, client application, and token handling for common misconfigurations
that enable account takeover or unauthorized access. Use when working with testing
oauth2 implementation flaws.
domain: cybersecurity
tags:
- api-security
- oauth2
- oidc
- authentication
- redirect-uri
- token-security
subdomain: api-security
version: 1.0.0
author: oyi77
license: Apache-2.0
nist_csf:
- PR.PS-01
- ID.RA-01
- PR.DS-10
- DE.CM-01
category: cybersecurity
---
# Testing Oauth2 Implementation Flaws
## Overview
Cybersecurity skill for testing oauth2 implementation flaws. Follows industry best practices and security standards.
## When to Use
**Trigger phrases:**
- "testing oauth2 implementation flaws"
- "Tests OAuth 2"
- Assessing OAuth 2.0 authorization code flow for redirect URI validation weaknesses
- Testing OAuth client applications for CSRF protection (state parameter usage) and PKCE enforcement
- Evaluating token storage, transmission, and lifecycle management in OAuth implementations
- Testing scope escalation where clients request more permissions than authorized
- Assessing OpenID Connect implementations for ID token validation and nonce usage
**Do not use** without written authorization. OAuth testing may result in token theft or unauthorized access.
## When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
## Prerequisites
- Written authorization specifying the OAuth provider and client applications in scope
- Test OAuth client registered with the authorization server
- Burp Suite Professional for intercepting OAuth redirects and token flows
- Python 3.10+ with `requests` and `oauthlib` libraries
- Browser developer tools for observing OAuth redirect chains
- Knowledge of the OAuth 2.0 grant types in use (authorization code, implicit, client credentials)
## Workflow
```python
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
```
1. **Reconnaissance** — Gather information about the target related to oauth2 implementation flaws. Identify attack surface.
2. **Vulnerability Identification** — Enumerate potential oauth2 implementation flaws weaknesses using automated and manual techniques.
3. **Exploit Development/Selection** — Choose or develop exploits targeting identified oauth2 implementation flaws vulnerabilities.
4. **Execution** — Execute the oauth2 implementation flaws test in a controlled manner with proper authorization.
5. **Post-Exploitation** — Document the impact and extent of successful exploitation.
6. **Reporting** — Write detailed findings with reproduction steps, impact assessment, and remediation guidance.
## Tools
- **Vulnerability Scanner** — Automated weakness identification
- **Exploitation Framework** — Controlled exploitation testing
- **Reporting Tool** — Findings documentation and tracking
## Process
1. **Design** — Define interface, identify patterns, plan implementation
1. **Implement** — Write code following existing conventions, add tests
1. **Verify** — Run tests, check integration, validate behavior
## Verification
- [ ] All oauth2 implementation flaws procedures executed completely and documented
- [ ] Findings validated against multiple data sources
- [ ] False positives identified and filtered
- [ ] Results documented with evidence and timestamps
- [ ] Recommendations provided with risk-based prioritization
## Anti-Rationalization Table
| Rationalization | Reality |
|---|---|
| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |
| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!