LogoClawIndex
CasesSkillsAbout
LogoClawIndex

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.

T1550.001_application-access-token - Use stolen application access tokens for authentication bypass

Use stolen application access tokens to bypass authentication and access restricted accounts, information, or services.

Tags

Updated: 2026-05-28

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • steal application access tokens
  • bypass authentication process
  • access restricted accounts
  • access restricted information
  • access restricted services
  • authorize API requests
  • use OAuth access token
  • search emails
  • enumerate contacts
  • trigger password reset
  • request short-lived access token
  • request data with token
  • perform actions with token
  • create federated user session

Inputs

  • target environment
  • SaaS systems
  • containers systems
  • IaaS systems
  • OAuth access token
  • cloud email service
  • user account
  • refresh token
  • REST API
  • AWS API credentials
  • AWS API call
  • user permissions
  • cloud account
  • user credentials
  • service provider
  • network perimeter
  • audit logs
  • third-party applications
  • corporate policies
  • user email

Outputs

  • access to resources
  • long-term access to features
  • extended access to services
  • short-lived access token
  • data from services
  • actions performed by user
  • federated user session
  • audit reports
  • encrypted email communications

Requirements

  • SaaS environment
  • containers environment
  • IaaS environment
  • Office Suite
  • Identity Provider
  • OAuth framework
  • AWS environment
  • GCP environment
  • user permissions
  • data perimeter
  • token binding strategy
  • file encryption

Source

  • Spec: SKILL.md
mitre-attack
enterprise
defense-evasion
lateral-movement
saas
containers
iaas
office-suite
identity-provider
oauth
cloud
application-access-token
steal application access tokens
bypass authentication process
access restricted accounts
access restricted information
target environment
SaaS systems
containers systems
access to resources
long-term access to features
extended access to services