Use when managing Connected Apps for integration purposes — configuring OAuth policies, IP restrictions, refresh token expiry, pre-authorization assignment via profile or permission set, and monitoring connected app usage via EventLogFile. Also covers the running-integration operations: revoking a grant, rotating the consumer key or secret, pairing the app to an integration user's permission set, and the periodic review. Trigger keywords: 'revoke OAuth token', 'DeleteToken', 'OauthToken query returns nothing', 'ipRelaxation ENFORCE', 'permissionSetName', 'PermissionSetAssignment ExpirationDate', 'LoginHistory Application', 'connected app quarterly review', 'rotate consumer secret'. NOT for choosing which OAuth grant flow to implement — use integration/oauth-flows-and-connected-apps. NOT for decoding a specific OAuth error such as invalid_grant — use admin/connected-app-troubleshooting. NOT for authoring the full connectedApp / External Client App / Named Credential file or choosing the auth artefact — use admin/connected-apps-and-auth.
日本語の概要は準備中です。原文の説明を表示しています。
PranavNagrecha/AwesomeSalesforceSkills☆ 192026年10月4日 更新
Troubleshooting Connected App OAuth flows — IP relaxation vs IP restriction, refresh token policy traps (default kills the connection on first refresh), session-revocation semantics, the OAuth error-code catalog (`invalid_grant`, `invalid_client_id`, `unsupported_grant_type`), per-user vs admin-pre-approved flows, and the user-policy check (Connected App must be assigned to the user via profile / permset). Covers the Login History debug trail. NOT for designing the OAuth flow itself — use integration/oauth-flows-and-connected-apps. NOT for a SAML / SSO login failure — use security/sso-saml-troubleshooting. Trigger keywords: 'invalid_grant', 'OAUTH_APP_BLOCKED', 'redirect_uri_mismatch', 'LoginHistory Status', 'LoginSubType', 'OauthRefreshToken', 'ForwardedForIp', 'SetupAuditTrail connected app', 'refreshTokenPolicy zero', 'isSecretRequiredForRefreshToken', 'works once then fails', 'diagnosis record'.
日本語の概要は準備中です。原文の説明を表示しています。
PranavNagrecha/AwesomeSalesforceSkills☆ 192026年10月4日 更新
Configure OAuth providers (Google, Apple, Microsoft, Facebook, GitHub, etc.) to work with portless local dev URLs. Use when setting up OAuth redirect URIs, fixing "redirect_uri_mismatch" or "invalid redirect" errors, configuring sign-in providers for local development, or when a provider rejects .localhost subdomains. Triggers include "OAuth not working with portless", "redirect URI mismatch", "Google/Apple/Microsoft sign-in fails locally", "configure OAuth for local dev", or any task involving OAuth callback URLs with portless domains.
日本語の概要は準備中です。原文の説明を表示しています。
vercel-labs/portless☆ 1.3万2026年10月8日 更新
Google OAuth クライアント設定の手順を案内する。「OAuth 設定」「Google 認証の準備」「クライアント ID 作成」「認証手順を教えて」「Google ログイン準備」「OAuth セットアップ」「認証設定したい」などで起動。
shiiman/claude-code-plugins☆ 62026年6月17日 更新
Tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass. The tester evaluates the authorization server, client application, and token handling for common misconfigurations that enable account takeover or unauthorized access. Activates for requests involving OAuth security testing, OIDC vulnerability assessment, OAuth2 redirect bypass, or aut...
日本語の概要は準備中です。原文の説明を表示しています。
MustafaKemal0146/fetih☆ 52026年10月11日 更新
Configures secure OAuth 2.0 authorization flows, including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant, covering flow selection, PKCE implementation, token lifecycle management, and scope design per OAuth 2.1. Use when implementing or hardening OAuth 2.0 authentication/authorization for web, mobile, SPA, or machine-to-machine clients.
日本語の概要は準備中です。原文の説明を表示しています。
mukul975/Anthropic-Cybersecurity-Skills☆ 3.4万2026年8月31日 更新
Maintain upstream OAuth identity-provider directive parsers, shared configuration dispatch, OAuth/OIDC discovery, GitHub identity claims, JWKS and static public PEM verification, EdDSA/Ed25519 token validation, key refresh, and real portal OAuth E2E tests. Excludes portal signing-key publication and gatekeeper-owned direct OAuth sessions.
日本語の概要は準備中です。原文の説明を表示しています。
greenpau/go-authcrunch☆ 602026年10月11日 更新
Deep OAuth 2.0 / OpenID Connect security assessment. Covers the full attack surface: redirect_uri validation bypass (path traversal, open redirect chains, subdomain confusion, URL parsing tricks, parameter pollution, response mode switching), missing/broken state parameter CSRF, PKCE downgrade and absent-challenge attacks, implicit grant token leakage (Referer, browser history, XSS fragment theft), authorization code injection, scope escalation, client confusion attacks, mutable-claims account takeover (iss+sub confusion, email-keyed identity merging), pre-account takeover via unverified registration, OpenID Connect dynamic client registration SSRF (logo_uri, jwks_uri, sector_identifier_uri, request_uri), nonce replay, ID token validation failures, Device Code phishing flow, mobile custom URI scheme hijacking, refresh token persistence, token introspection enumeration, consent screen clickjacking, host header injection, and cross-IdP mix-up attacks. Uses KOAuth, jwt_tool, nuclei oauth templates, and manual http(action="request", ...) payloads. Every technique includes actual request payloads and verification logic. Chains from /pentester or /api-security when OAuth endpoints are discovered. Chains into /web-exploit for open redirect, XSS, and SSRF chaining. Chains into /post-exploit when full account takeover is achieved. Chains into /credential-audit when access tokens or refresh tokens are recovered.
日本語の概要は準備中です。原文の説明を表示しています。
ShulkwiSEC/bb-huge☆ 242026年7月11日 更新
Use when designing, reviewing, or troubleshooting Salesforce connected apps, External Client Apps, Named Credentials, External Credentials, and OAuth-based integration access. Triggers: 'connected app', 'OAuth flow', 'client credentials', 'JWT bearer', 'Named Credential', 'External Credential', 'integration user', 'IP restrictions', 'connectedApp-meta.xml', 'ExternalClientApplication', 'ExtlClntAppOauthSettings', 'isAdminApproved', 'refreshTokenPolicy', 'ipRelaxation', 'consumer key', 'consumer secret', 'permittedUsersPolicyType'. NOT for OAuth error codes you are already seeing — use admin/connected-app-troubleshooting. NOT for External Credential principal-type setup steps — use integration/named-credentials-setup.
日本語の概要は準備中です。原文の説明を表示しています。
PranavNagrecha/AwesomeSalesforceSkills☆ 192026年10月4日 更新
Implement and debug OAuth 2.0 DPoP (RFC 9449) refresh token sender-constraining for WebCrypto, Node.js ES6, and browser runtimes integrating with Google's OAuth platform. Use when configuring non-extractable asymmetric key pairs (P-256), generating DPoP Proof JWTs for authorization code exchange and token refresh, or handling 400 use_dpop_nonce challenge retry loops at oauth2.googleapis.com/token. Don't use for unconstrained OAuth 2.0 flows (where refresh tokens are not bound to a client key pair), or for Google Cloud IAM / service account authentication.
日本語の概要は準備中です。原文の説明を表示しています。
google/skills☆ 2.1万2026年10月10日 更新
Emulated Microsoft Entra ID (Azure AD) OAuth 2.0 / OpenID Connect for local development and testing. Use when the user needs to test Microsoft sign-in locally, emulate Entra ID OIDC discovery, handle Microsoft token exchange, configure Azure AD OAuth clients, work with Microsoft Graph /me, or test PKCE/client credentials flows without hitting real Microsoft APIs. Triggers include "Microsoft OAuth", "Entra ID", "Azure AD", "emulate Microsoft", "mock Microsoft login", "test Microsoft sign-in", "Microsoft OIDC", "local Microsoft auth", or any task requiring a local Microsoft OAuth/OIDC provider.
日本語の概要は準備中です。原文の説明を表示しています。
vercel-labs/emulate☆ 1,8832026年10月10日 更新
Expert guidance on authentication implementation including OAuth 2.0/OIDC, JWT tokens, session management, and secure password handling. Covers both implementing auth from scratch and integrating auth providers. Use when "implement authentication, oauth login, jwt tokens, session management, social login, password reset, multi-factor auth, refresh tokens, Working with Auth0, Clerk, NextAuth, Passport.js, authentication, oauth, jwt, session, security, login, password, mfa, oidc" mentioned.
日本語の概要は準備中です。原文の説明を表示しています。
omer-metin/skills-for-antigravity☆ 1642026年1月22日 更新
Hunt OAuth 2.0 and OIDC flaws — redirect_uri abuse, state CSRF, PKCE bypass, scope manipulation, implicit-flow token theft, postMessage origin tricks, ID token sub claim swap, JWKS confusion, response_type confusion, and OAuth-CSRF. Use when an app has Google/GitHub/Facebook/Apple/custom OAuth or OpenID Connect.
日本語の概要は準備中です。原文の説明を表示しています。
0xGhostCAT/claude-ai-cyber-security-skills☆ 422026年6月3日 更新
Identify and exploit logic flaws in OAuth implementations, focusing specifically on the absence or improper validation of the `state` parameter, which leads to Cross-Site Request Forgery (CSRF) and account takeover (ATO).
日本語の概要は準備中です。原文の説明を表示しています。
ShulkwiSEC/bb-huge☆ 242026年7月11日 更新
Implement and debug OAuth 2.0 DPoP (RFC 9449) refresh token sender-constraining for WebCrypto, Node.js ES6, and browser runtimes integrating with Google's OAuth platform. Use when configuring non-extractable asymmetric key pairs (P-256), generating DPoP Proof JWTs for authorization code exchange and token refresh, or handling 400 use_dpop_nonce challenge retry loops at oauth2.googleapis.com/token. Don't use for unconstrained OAuth 2.0 flows (where refresh tokens are not bound to a client key pair), or for Google Cloud IAM / service account authentication.
日本語の概要は準備中です。原文の説明を表示しています。
vaila-multimodaltoolbox/vaila☆ 192026年10月8日 更新
Webアプリのアクセス制御・認証・認可の実装はすべてこのスキルを使う。遮断だけならCloudflare Access、アプリ内identity・role・session・WebSocket等が必要ならBetter Authとする単一決定表の正本。「認証を付けて」「ログイン機能」「Googleでログインできるように」「社員だけに限定」「特定企業だけに公開」「許可リスト/招待制」「メール+パスワード認証」「セッション管理」「ロール・権限管理」「OAuth設定」「redirect_uri_mismatchを直す」「認証のセキュリティレビュー」などの文脈で、ユーザーが「認証」と明示しなくてもログイン要件が含まれるなら必ず読む。特にNext.js App Router+OpenNext+D1、Hono、素のWorkersでのBetter Auth+Google OAuth導入を自動化し、Google Cloud Consoleで人間にしかできない操作は日本語のクリック手順と直リンクへ切り分ける。
daishiman/harness-dev☆ 102026年10月10日 更新
Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID (Azure AD) token protection, conditional access policies, and sign-in anomaly detection. Covers access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, and pass-the-cookie attacks. Activates for requests involving OAuth token theft detection, token replay prevention, Azure AD conditional access token protection, or cloud identity attack investigation.
日本語の概要は準備中です。原文の説明を表示しています。
andycungkrinx91/konoha☆ 92026年10月9日 更新
tespit etme (s) and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID (Azure AD) token protection, conditional access policies, and sign-in anomaly Tespit. Covers access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, and pass-the-cookie attacks. Activates for requests involving OAuth token theft Tespit, token replay prevention, Azure AD conditional access token protection, or cloud identity attack investigation.
日本語の概要は準備中です。原文の説明を表示しています。
MustafaKemal0146/fetih☆ 52026年10月11日 更新
Guide for adding new OAuth-based integrations to Fabric. Use when implementing OAuth providers like Microsoft Teams, GitHub, Google Drive, Slack, or similar services that need OAuth 2.0 authentication for user data access.
日本語の概要は準備中です。原文の説明を表示しています。
Fabric-Pro/fabric-oss☆ 32026年10月9日 更新
Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID (Azure AD) token protection, conditional access policies, and sign-in anomaly detection. Covers access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, and pass-the-cookie attacks. Activates for requests involving OAuth token theft detection, token replay prevention, Azure AD conditional access token protection, or cloud identity attack investigation.
日本語の概要は準備中です。原文の説明を表示しています。
aniket2348823/Vul-Agent☆ 22026年6月9日 更新
OAuth 2.0 attack checklist: authorization code interception, redirect_uri bypass, CSRF on OAuth flow, state parameter abuse, open redirector chaining, token leakage via Referer, PKCE bypass, and scope escalation. Use when testing OAuth implementations in web apps or bug bounty.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
X(Twitter)の投稿、スレッド公開、タイムライン取得、検索、反応の集計をAPIで行うスキル。認証の設定や利用上限への対応、画像付き投稿も扱います。
- APIで投稿やスレッド、画像を公開
- タイムラインやユーザー情報の取得
- 話題や会話に関する投稿を検索したいとき
affaan-m/ECC☆ 27.7万2026年10月5日 更新
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for OAuth, OIDC, redirect flows, state or nonce handling, PKCE, token exchange, refresh logic, claim mapping, and accepted login paths. Use when the user asks to trace redirects, callback parameters, scopes, state, nonce, PKCE, refresh tokens, consent, or explain how an OAuth or OIDC chain turns into accepted identity or privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
日本語の概要は準備中です。原文の説明を表示しています。
zhaoxuya520/reverse-skill☆ 4.1万2026年9月22日 更新
Detect and respond to OAuth token theft and replay in Microsoft Entra ID (Azure AD), covering access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, pass-the-cookie attacks, and Token Protection conditional access policies. Use for impossible-travel or anomalous token-usage alerts, suspected session hijacking, sign-in log analysis, or configuring token-binding defenses in Azure/M365.
日本語の概要は準備中です。原文の説明を表示しています。
mukul975/Anthropic-Cybersecurity-Skills☆ 3.4万2026年8月31日 更新