Skip to main content

Browser Auth Flow

Skill Verified Active

Probe a site's authentication flow for redirect leaks, missing CSRF, weak session cookies, and OAuth misconfiguration; produces an auth findings.md

Purpose

To provide a thorough, automated security audit of web application authentication mechanisms before deployment or during security investigations.

Features

  • Probes for redirect leaks
  • Detects missing CSRF tokens
  • Analyzes session cookie security (Secure, HttpOnly, SameSite)
  • Checks OAuth misconfigurations (state, nonce, redirect_uri)
  • Generates a structured `findings.md` report
  • Supports credential management via handles

Use Cases

  • Performing pre-deployment security audits of new authentication flows.
  • Investigating suspected token leaks or redirect vulnerabilities.
  • Establishing a baseline for regression testing of authentication security.
  • Validating the security posture of OAuth implementations.

Non-Goals

  • Exploiting vulnerabilities or chaining follow-up requests with captured tokens.
  • Hardcoding credentials; requires vaulted handles or interactive entry.
  • Performing full penetration testing beyond authentication flow analysis.

Practical Utility

  • info:Usage examplesWhile the SKILL.md outlines the steps and probes, concrete end-to-end examples with input, invocation, and output are not explicitly provided.

Installation

First, add the marketplace

/plugin marketplace add ruvnet/ruflo
/plugin install ruflo-browser@ruflo

Quality Score

Verified
96 /100
Analyzed about 17 hours ago

Trust Signals

Last commitabout 18 hours ago
Stars50.2k
LicenseMIT
Status
View Source

Similar Extensions

Investigate Capa Root Cause

100

Investigate root causes and manage CAPAs (Corrective and Preventive Actions) for compliance deviations. Covers investigation method selection (5-Why, fishbone, fault tree), structured root cause analysis, corrective vs preventive action design, effectiveness verification, and trend analysis. Use when an audit finding requires a CAPA, when a deviation or incident occurs in a validated system, when a regulatory observation needs a formal response, when a data integrity anomaly requires investigation, or when recurring issues suggest a systemic root cause.

Skill
pjt222

Soul Guardian

100

Drift detection + baseline integrity guard for agent workspace files with automatic alerting support

Skill
prompt-security

Audit Dependency Versions

100

Audit project dependencies for version staleness, security vulnerabilities, and compatibility issues. Covers lock file analysis, upgrade path planning, and breaking change assessment. Use before a release to ensure dependencies are current and secure, during periodic maintenance reviews, after receiving a security advisory, when upgrading to a new language version, before submitting to CRAN or npm, or when inheriting a project to assess its dependency health.

Skill
pjt222

Toprank Weekly Review

100

Run a weekly SEO review for one registered website, write audit artifacts, and choose the next best safe action.

Skill
nowork-studio

Janitor Tokens

100

Show how many context window tokens each skill consumes. Use when the user asks about token cost, context budget, skill size, or wants to know which skills waste the most context space.

Skill
khendzel

Janitor Report

100

Full health check of all your skills in one report. Use when the user wants to check for errors, find duplicates, detect broken skills, or get a complete overview of skill health.

Skill
khendzel

© 2025 SkillRepo · Find the right skill, skip the noise.