attacking-oauth-with-device-code-phishing

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a specialized utility for authorized security testing that automates the OAuth 2.0 device authorization grant flow against Microsoft Entra ID.
  • [SAFE]: The helper script scripts/agent.py communicates exclusively with official Microsoft identity platform endpoints (login.microsoftonline.com) and uses standard Python modules for network and data handling.
  • [SAFE]: External tools referenced in the instructions, such as ROADtools and TokenTactics, are well-known and respected utilities within the cybersecurity community.
  • [SAFE]: The skill includes explicit legal notices and scopes its operations to authorized environments, focusing on token capture and impact demonstration for identity security testing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 02:41 PM
Security Audit — agent-trust-hub — attacking-oauth-with-device-code-phishing