yaklang/hack-skills

saml-sso-assertion-attacks

>- SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictions, ACS handling, XML trust boundaries, and enterprise SSO flaws.

All-time #4462 Trending #7325 First seen Apr 8, 2026
8-week activity · all time api

Installation

$ npx skills add yaklang/hack-skills --skill saml-sso-assertion-attacks

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from yaklang/hack-skills · top by installs.

npx skills add yaklang/hack-skills

Browse all from yaklang/hack-skills

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 2.1K
License LICENSE
Default branch main
Open issues 0
Status Active

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,000 B
  • docs SUMMARY.md 213 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 2,910 installs

SKILL.md

SKILL: SAML SSO and Assertion Attacks — Signature Validation, Binding, and Trust Confusion

AI LOAD INSTRUCTION: Use this skill when the target uses SAML-based SSO and you need to validate assertion trust: signature coverage, audience and recipient checks, ACS handling, XML parsing weaknesses, and IdP/SP confusion.

1. WHEN TO LOAD THIS SKILL

Load when:

  • Enterprise SSO uses SAML requests or responses
  • You see SAMLRequest, SAMLResponse, XML assertions, or ACS endpoints
  • Login flows involve an external IdP and browser POST/redirect binding

2. HIGH-VALUE MISCONFIGURATION CHECKS

Theme What to Check
signature validation unsigned assertion accepted, wrong node signed, signature wrapping
audience and recipient weak Audience, Recipient, Destination, or ACS validation
issuer trust wrong IdP accepted or multi-tenant issuer confusion
replay and freshness missing InResponseTo, weak NotBefore / NotOnOrAfter enforcement
account mapping email-only binding, case folding, unverified attributes
XML parser behavior XXE-like parser issues or unsafe transforms around SAML documents

3. QUICK TRIAGE

  1. Capture one full login round trip.
  2. Inspect which XML nodes are signed and which attributes drive account binding.
  3. Compare SP-initiated and IdP-initiated flows.
  4. Test replay, altered attributes, and assertion placement confusion.

4. RELATED ROUTES

  • XML parser attack depth: [xxe xml external entity](../xxe-xml-external-entity/SKILL.md)
  • OAuth or OIDC SSO alternatives: [oauth oidc misconfiguration](../oauth-oidc-misconfiguration/SKILL.md)
  • Auth boundary issues after SSO: [authbypass authentication flaws](../authbypass-authentication-flaws/SKILL.md)