wgpsec/aboutsecurity
oauth-sso-attack
OAuth 2.0 / SSO / OpenID Connect 认证流程攻击。当目标有「使用 Google/GitHub/微信 登录」按钮、redirect_uri 参数、authorization_code 流程、或 /.well-known/openid-configuration 端点时使用。覆盖…
Installation
npx skills add https://github.com/wgpsec/aboutsecurity
Similar popular skills
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
Use when Codex is already in the attack-path-analysis phase of a security scan or the user expl…
287 installsBuild comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, …
11.9K installs>- JWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, ke…
3.1K installs>- HTTP Host header injection and routing abuse playbook. Use when the application trusts the H…
2.9K installs>- SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrappin…
2.9K installs>- Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-R…
2.9K installsAlso in this package
Other skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
More details
Agent compatibility
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Repository health
master
History
- First seen on skills.sh
- First recorded snapshot · 20 installs