LogoClawIndex
CasesSkillsAbout
LogoClawIndex

hunt-oauth - Hunt for OAuth vulnerabilities

Enumerates OAuth surfaces and tests redirect URIs, state, nonce, authentication flows, referrer leakage, mobile deep links, and client credentials.

Tags

Updated: 2026-10-06

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Enumerate OAuth entry points
  • Map OAuth authorization flows
  • Test redirect URI validation
  • Test state CSRF protection
  • Test nonce validation
  • Test authentication step ordering
  • Check referrer token leakage
  • Test mobile deep links
  • Check client credential exposure
  • Verify and document findings

Inputs

  • Target application
  • OAuth endpoints
  • JavaScript bundles
  • Mobile APK files
  • OAuth requests and responses
  • Burp history
  • Callback page resources

Outputs

  • OAuth vulnerability findings
  • Verified exploit evidence
  • Documented security report

Requirements

  • Target testing access
  • JavaScript or APK inspection tools
  • HTTP request testing tools
  • Android debugging tools for deep-link tests

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
OAuth
OpenID Connect
Web security
Mobile security
Account takeover
CSRF
Deep links
Enumerate OAuth entry points
Map OAuth authorization flows
Test redirect URI validation
Test state CSRF protection
Target application
OAuth endpoints
JavaScript bundles
OAuth vulnerability findings
Verified exploit evidence
Documented security report