SkillsLib.ai

Authentication Flow Reviewer

Audit authentication code for JWT, session, OAuth2, and MFA vulnerabilities

4.3(53 reviews)
1,000+ downloads
Updated Sep 2026
Verified SafeSecurity VerifiedThis skill was analyzed by our AI security scanner for harmful content including data exfiltration, system manipulation, credential theft, and prompt injection. No threats were detected.

What You Can Do

You can submit authentication and authorization code implementations for deep security analysis. The skill examines JWT implementations, session management patterns, password hashing strategies, MFA mechanisms, and OAuth2/OIDC configurations to identify structural vulnerabilities, configuration weaknesses, and implementation flaws that could lead to account compromise or unauthorized access. It produces severity-rated vulnerability reports with reproducible attack scenarios and specific remediation steps.

Features

JWT vulnerability detection

identifies signature verification gaps, key management issues, expiration handling flaws, and algorithm coercion attacks

Session management auditing

detects token storage risks, invalidation gaps, fixation vulnerabilities, and insecure cookie configurations

Password storage analysis

reviews hashing algorithms, salt usage, iteration counts, and storage patterns against current standards

MFA mechanism review

uncovers bypass vectors, recovery code weaknesses, timing attack risks, and enforcement gaps

OAuth2/OIDC configuration audit

validates state parameters, redirect URI security, token endpoint protection, and scope handling

Authorization logic assessment

analyzes permission checks, role inheritance models, and attribute-based access control (ABAC) implementation gaps

Severity-rated reporting

categorizes findings by exploitability and impact with specific remediation guidance

Example Output

Example 1: JWT Vulnerability Report

Finding: Weak Key Management (High Severity)

  • Issue: RS256 algorithm configured but private key stored in environment variable with read access across multiple services
  • Attack Scenario: Service compromise allows attacker to sign arbitrary JWTs with any claims
  • Remediation: Migrate keys to secure vault (HashiCorp, AWS KMS). Rotate immediately. Implement key versioning for algorithm rotation.

Example 2: Session Management Issue

Finding: Missing Session Invalidation on Logout (Medium Severity)

  • Issue: Session tokens remain valid for full expiration period even after user-initiated logout
  • Attack Scenario: Attacker gains token and can maintain access indefinitely if user logs out thinking they've terminated the session
  • Remediation: Implement token blacklist or short-lived refresh token rotation on logout.

Example 3: OAuth2 Configuration Gap

Finding: Insufficient Redirect URI Validation (High Severity)

  • Issue: Redirect URI accepts wildcard subdomains (*.example.com) allowing open redirect to attacker-controlled subdomains
  • Attack Scenario: Attacker registers subdomain and captures authorization codes
  • Remediation: Use exact string matching for redirect URIs. Reject wildcard patterns.

What's Included

  • SKILL.md: Complete authentication security audit framework and vulnerability taxonomy
  • JWT Checklist: Signature algorithms, key management, expiration, and token structure validation points
  • Session Security Template: Token storage, invalidation, rotation, and cookie configuration review template
  • OAuth2/OIDC Flow Diagram: Reference architecture for state validation, authorization code, and token endpoint security
  • Severity Scoring Framework: CVSS-aligned ratings and remediation priority guidance

Who It's For

  • Security engineers and AppSec teams — conducting pre-deployment code reviews and threat modeling sessions
  • Backend/API developers — validating custom authentication implementations before production release
  • DevOps/platform engineers — auditing identity service configurations and access control policies
  • Security architects — assessing third-party authentication system integrations and OAuth2/OIDC flows
  • Compliance and risk teams — documenting authentication security controls for audit and certification

Best For

  • Custom JWT implementation reviews and signature verification audits
  • Session management and token storage architecture assessments
  • OAuth2/OIDC flow validation and redirect URI configuration audits
  • MFA mechanism bypass risk analysis and enforcement gap identification
  • Password storage and hashing algorithm compliance reviews
  • Authorization logic and permission check implementation verification
  • Pre-deployment security assessments for authentication-critical features

You might also like

Screenpipe Api
$25
Backend4.4(49)
Screenpipe Api

Query your local Screenpipe instance to retrieve screen recordings, audio transcriptions, UI element accessibility trees, keyboard/mouse input logs, and productivity analytics. You can search by keywords, filter by content type (audio, OCR, accessibility, input), set time ranges, and extract structured data about your applications, meetings, and work sessions without sending data to external servers.

Commercial Code Compliance Analyzer
$45
Commercial3.9(27)
Commercial Code Compliance Analyzer

You can submit architectural design documents, floor plans, and project parameters to receive a comprehensive compliance analysis that cross-references IBC, local amendments, zoning ordinances, and ADA accessibility requirements. Claude identifies specific gaps, cites applicable code sections, explains why each gap matters, and provides concrete remediation strategies—all before formal design review submission when corrections are costly and schedule-impacting.

Seismic Hazard Assessment & Ground Motion Analysis
$35
Earthquake4.2(35)
Seismic Hazard Assessment & Ground Motion Analysis

You can leverage Claude to synthesize regional seismic hazard data from authoritative sources (USGS maps, published studies), interpret probabilistic versus deterministic earthquake scenarios, and analyze how site conditions modify ground motions. Claude helps you justify seismic design parameters to clients and regulators, evaluate liquefaction and earthquake-induced landslide risks, and develop defensible recommendations aligned with ASCE 7 and current guidelines—accelerating report preparation without replacing specialized geotechnical software.

IDP Developer Experience Audit & Friction Point Analysis
$40
IDP Developer Experience Audit & Friction Point Analysis

You systematically evaluate your internal developer platform across dimensions like onboarding, deployment, tooling, and documentation to identify quantifiable friction points. Claude analyzes your platform's usability, creates a friction scoring matrix, and generates a prioritized improvement roadmap ranked by team impact and implementation effort. You get a data-driven strategy to reduce developer toil and accelerate delivery.

Timber Structural Analysis Assistant
$30
Timber3.7(29)
Timber Structural Analysis Assistant

This skill enables you to rapidly produce structural analyses for timber members, including bending, shear, compression, and combined stress calculations. You can determine lateral load capacity for shear walls, design connections, evaluate code compliance against NDS standards, assess serviceability limits, and generate calculation frameworks suitable for permit submission and engineer stamping.

Earth Retention System Designer
$35
Earth Retention System Designer

Design earth retention systems by inputting soil properties, site geometry, and regulatory requirements. Claude calculates lateral earth pressures using Coulomb, Rankine, and Mononobe-Okabe methods, verifies factors of safety for internal and external stability, compares competing retention concepts (gravity walls, cantilever, anchored, sheet-pile, soil-nail), and generates cost-benefit analysis and regulatory documentation packages ready for permit submission.

Owasp Security Scanner
$30
AppSec4.4(49)
Owasp Security Scanner

You can submit codebases in Python, JavaScript/Node.js, Java, PHP, Go, Ruby, or C# for comprehensive vulnerability scanning. Claude identifies specific vulnerability instances with line numbers, assigns severity ratings (Critical to Low) based on exploitability, and generates secure code alternatives. The skill produces structured reports prioritized by risk, complete with root cause analysis and testing recommendations.

HVAC Load Calculation & Equipment Sizing Assistant
$30
HVAC3.9(32)
HVAC Load Calculation & Equipment Sizing Assistant

You can accelerate HVAC design workflows by inputting building parameters—envelope characteristics, occupancy data, climate conditions, and existing systems—and receiving calculated heating/cooling loads, equipment sizing recommendations, and zone-by-zone analysis. Claude organizes complex building data into actionable design parameters and specification summaries for client review, permit submission, and professional validation against ASHRAE and ACCA standards.

$35.00