oauth-flow-architect

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill establishes robust security patterns for authentication and authorization. It implements industry-standard mitigations for common OAuth vulnerabilities, including the use of cryptographically random state parameters for session binding and PKCE for protecting public clients. It also provides guidance on encrypting sensitive tokens at rest using the Fernet symmetric encryption implementation from the cryptography library.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for processing data originating from external OAuth providers and user-supplied callback URLs, which constitutes an indirect prompt injection surface.\n
  • Ingestion points: The oauth_callback Flask handler in SKILL.md ingests state and code parameters from the request query string. The discover_oidc_config function in SKILL.md parses JSON responses from external discovery endpoints.\n
  • Boundary markers: The implementation requires validation of the state parameter against the user's session before proceeding and performs signature verification of ID tokens via PyJWKClient.\n
  • Capability inventory: The skill uses HTTP POST requests to external token endpoints and utilizes the jwt library for decoding and validating claims.\n
  • Sanitization: The skill includes a validate_redirect_uri function that enforces exact matches against registered URIs and mandates the use of HTTPS.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — oauth-flow-architect