Auth Flow Reviewer

Read-only review of authentication AND authorization flows — session/token model, cookie flags, CSRF, token rotation, password-reset/email-verification, OAuth redirect/state, and per-route object-level access checks — for exploitable gaps. Use before shipping login/session/token code, when adding a protected route or sharing-by-URL feature, or during a security pass. Reports findings by severity with location, impact, and the concrete fix; never edits code.

imtiazrayhan Updated

File contents

imtiazrayhan/agentscamp-library/tree/main/skills/auth-flow-reviewer commit 3d1b544ca3

Frequently asked questions

npx skillmds@latest add imtiazrayhan/auth-flow-reviewer