oauth-flow-architect
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill establishes robust security patterns for authentication and authorization. It implements industry-standard mitigations for common OAuth vulnerabilities, including the use of cryptographically random state parameters for session binding and PKCE for protecting public clients. It also provides guidance on encrypting sensitive tokens at rest using the Fernet symmetric encryption implementation from the cryptography library.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for processing data originating from external OAuth providers and user-supplied callback URLs, which constitutes an indirect prompt injection surface.\n
- Ingestion points: The
oauth_callbackFlask handler inSKILL.mdingestsstateandcodeparameters from the request query string. Thediscover_oidc_configfunction inSKILL.mdparses JSON responses from external discovery endpoints.\n - Boundary markers: The implementation requires validation of the
stateparameter against the user's session before proceeding and performs signature verification of ID tokens viaPyJWKClient.\n - Capability inventory: The skill uses HTTP POST requests to external token endpoints and utilizes the
jwtlibrary for decoding and validating claims.\n - Sanitization: The skill includes a
validate_redirect_urifunction that enforces exact matches against registered URIs and mandates the use of HTTPS.
Audit Metadata