hunt-oauth - Hunt for OAuth vulnerabilities
Enumerates OAuth surfaces and tests redirect URIs, state, nonce, authentication flows, referrer leakage, mobile deep links, and client credentials.
Tags
Updated: 2026-10-06Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Enumerate OAuth entry points
- Map OAuth authorization flows
- Test redirect URI validation
- Test state CSRF protection
- Test nonce validation
- Test authentication step ordering
- Check referrer token leakage
- Test mobile deep links
- Check client credential exposure
- Verify and document findings
Inputs
- Target application
- OAuth endpoints
- JavaScript bundles
- Mobile APK files
- OAuth requests and responses
- Burp history
- Callback page resources
Outputs
- OAuth vulnerability findings
- Verified exploit evidence
- Documented security report
Requirements
- Target testing access
- JavaScript or APK inspection tools
- HTTP request testing tools
- Android debugging tools for deep-link tests
