All skills
sergiodxa avatar

/owasp-security-check

@40e21b4

Security audit guidelines for web applications and REST APIs based on OWASP Top 10 and web security best practices. Use when checking code for vulnerabilities, reviewing auth/authz, auditing APIs, or before production deployment.

Use this Skill: https://skilld.dev/gh/sergiodxa/agent-skills/owasp-security-check

This session only. Nothing lands on disk.

rulesredirect-validation.md

≈747 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Open Redirect Prevention

Check for unvalidated redirect and forward URLs that could be used for phishing attacks.

Related: SSRF prevention (server-side URL validation) is covered in ssrf-attacks.md.

Why

  • Phishing attacks: Legitimate domain redirects to malicious site
  • Credential theft: Users trust your domain and enter credentials
  • OAuth attacks: Redirect after auth to steal tokens
  • Trust abuse: Your domain's reputation exploited

What to Check

Vulnerability Indicators:

  • Redirect URLs from query parameters
  • No validation of redirect target
  • External redirects allowed without warning
  • OAuth return_uri not validated

Bad Patterns

// Bad: Unvalidated redirect
async function callback(req: Request): Promise<Response> {
  let url = new URL(req.url);
  let returnUrl = url.searchParams.get("return");

  // Attacker can set return=https://evil.com
  return Response.redirect(returnUrl!);
}

// Bad: No validation on OAuth callback
async function oauthCallback(req: Request): Promise<Response> {
  let url = new URL(req.url);
  let redirectUri = url.searchParams.get("redirect_uri");

  // Complete OAuth flow...

  return Response.redirect(redirectUri!);
}

Good Patterns

// Good: Validate against allowlist
const ALLOWED_REDIRECTS = ["/dashboard", "/profile", "/settings"];

async function callback(req: Request): Promise<Response> {
  let url = new URL(req.url);
  let returnUrl = url.searchParams.get("return") || "/";

  if (!ALLOWED_REDIRECTS.includes(returnUrl)) {
    return Response.redirect("/");
  }

  return Response.redirect(returnUrl);
}

// Good: Validate URL is relative
function isValidRedirect(url: string): boolean {
  return url.startsWith("/") && !url.startsWith("//");
}

async function callback(req: Request): Promise<Response> {
  let url = new URL(req.url);
  let returnUrl = url.searchParams.get("return") || "/";

  if (!isValidRedirect(returnUrl)) {
    return Response.redirect("/");
  }

  return Response.redirect(returnUrl);
}

// Good: Validate OAuth redirect_uri
const ALLOWED_OAUTH_REDIRECTS = [
  "https://app.example.com/callback",
  "https://admin.example.com/callback",
];

async function oauthCallback(req: Request): Promise<Response> {
  let url = new URL(req.url);
  let redirectUri = url.searchParams.get("redirect_uri");

  if (!redirectUri || !ALLOWED_OAUTH_REDIRECTS.includes(redirectUri)) {
    return new Response("Invalid redirect_uri", { status: 400 });
  }

  // Complete OAuth flow...
  return Response.redirect(redirectUri);
}

Rules

  1. Validate redirect URLs - Use allowlist
  2. Only allow relative URLs - Starts with / not //
  3. Never trust user input - For redirect targets
  4. Validate OAuth redirects - Pre-registered URIs only
  5. Default to safe redirect - Home page if invalid

Source: SKILL.md on GitHub

2 warnings15d5 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    The skill is a comprehensive security audit guide based on OWASP standards. It provides examples of vulnerable and secure code patterns for pedagogical use. The only identified risk is the inherent surface for indirect prompt injection when the agent processes untrusted user-provided code, although the skill lacks dangerous autonomous capabilities.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    21/21 files flagged

  • ZeroLeaks5mo

    3 findings · Score: 69/100

Signed by skilld at 40e21b4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Dormantupdated 8 months ago

README badge

README badge for sergiodxa/agent-skills/owasp-security-check