testing-oauth2-implementation-flaws

Installation
SKILL.md

Testing OAuth2 Implementation Flaws

When to Use

  • Assessing OAuth 2.0 authorization code flow for redirect URI validation weaknesses
  • Testing OAuth client applications for CSRF protection (state parameter usage) and PKCE enforcement
  • Evaluating token storage, transmission, and lifecycle management in OAuth implementations
  • Testing scope escalation where clients request more permissions than authorized
  • Assessing OpenID Connect implementations for ID token validation and nonce usage

Do not use without written authorization. OAuth testing may result in token theft or unauthorized access.

Prerequisites

  • Written authorization specifying the OAuth provider and client applications in scope
  • Test OAuth client registered with the authorization server
  • Burp Suite Professional for intercepting OAuth redirects and token flows
  • Python 3.10+ with requests and oauthlib libraries
  • Browser developer tools for observing OAuth redirect chains
  • Knowledge of the OAuth 2.0 grant types in use (authorization code, implicit, client credentials)
Related skills
Installs
53
GitHub Stars
6.3K
First Seen
Mar 15, 2026