browser-auth-flow
Probe a site's authentication flow for redirect leaks, missing CSRF, weak session cookies, and OAuth misconfiguration; produces an auth findings.md
Browser Auth Flow
Adversarial probe of a site's authentication. Drives the login flow once, records the trajectory, then runs a configurable set of probes against the captured artifacts and live page. Output is a structured findings.md inside the RVF container.
When to use
- Pre-deployment audit of a new auth flow.
- Investigating a suspected token leak or redirect issue.
- Establishing a baseline for ongoing regression checks.
Steps
-
Open a recorded session via
browser-record. -
Drive the auth flow as in
browser-login(credentials come from--credentials <handle>referencingbrowser-cookiesif the run is a re-auth probe). -
Run probes:
csrf: inspect the login POST in the trajectory; verify a same-origin token field is present and non-empty.redirect: watchbrowser_get-urlafter each nav for cross-origin redirects with auth state in the URL or fragment. Flag any token-bearing URL that crosses an origin boundary.cookie: walkdocument.cookieviabrowser_eval. For each cookie, checkSecure,HttpOnly,SameSite, expiry, and entropy of the value. Flag missing flags or short tokens. Pass each throughaidefence_scanto flag PII embedded in cookie values.oauth: if the flow involves a third-party provider, capture the authorization request, verifystateandnonceare present and high-entropy, verifyredirect_urimatches the registered callback domain.
-
Quarantine any token / credential / PII captured during probing — it stays inside the RVF container's findings, never returns to the model unredacted (
aidefence_is_safegate frombrowser-extractapplies if you read the findings back). -
Write
findings.mdwith one section per probe, severity rating per finding, and averdict(pass / warn / fail). -
Index the session in
browser-sessionswithtag: auth-probeso future audits compare against it.
Caveats
- This skill probes; it does not exploit. Do not chain follow-up requests using a captured token.
- Credentials must come from a vaulted handle or interactive entry. Never hardcode them in the field map.
- Some probes require multiple page loads. Trajectory step count for an auth probe typically lands at 15–40 steps; budget accordingly.
- The output is structured for human review. Do not auto-act on findings without surfacing them to the user first.
ruvnet/claude-flow · MIT · Revision 005a0ed25e64
Be the first to comment
Share what worked or leave a question for the creator.