detecting-oauth-token-theft

mukul975/detecting-oauth-token-theft · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID token protection, conditional access policies, and sign-in anomaly detection.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 1.6 KB
  • 📁scripts
  • ⚙️agent.py 7.0 KB
  • 📄LICENSE 11.0 KB

Related

  1. detecting-azure-service-principal-abuse · mukul975 bundle
    Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.
    24.6k
    repo stars
  2. auditing-azure-active-directory-configuration · mukul975 bundle
    Audit Microsoft Entra ID (Azure Active Directory) configuration for risky authentication policies, over-privileged role assignments, stale accounts, conditional access gaps, and guest user risks using PowerShell, Graph API, and ScoutSuite.
    24.6k
    repo stars
  3. post-exploiting-microsoft-graph-with-graphrunner · mukul975 bundle
    Perform reconnaissance, persistence, privilege escalation, and data pillaging on Microsoft 365/Entra ID tenants via the Microsoft Graph API using the GraphRunner PowerShell toolset.
    24.6k
    repo stars
  4. implementing-zero-trust-for-saas-applications · mukul975 bundle
    Enforce identity verification, device compliance, and data protection for cloud-hosted services using CASB, SSPM, conditional access policies, OAuth app governance, and session controls.
    24.6k
    repo stars
  5. detecting-suspicious-oauth-application-consent · mukul975 bundle
    Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks.
    24.6k
    repo stars
  6. entra-agent-id · microsoft bundle
    Create and manage OAuth2-capable identities for AI agents using Microsoft Graph beta API.
    2.7k
    repo stars

Frequently asked questions

How do I install the detecting-oauth-token-theft skill?

Run npx skillmds add mukul975/detecting-oauth-token-theft in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the detecting-oauth-token-theft skill do?

Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID token protection, conditional access policies, and sign-in anomaly detection. It is listed under Security, DevOps & Infra, Compliance & Privacy, Incident Response on SkillMD.

Is detecting-oauth-token-theft safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: CAUTION, Skill Scanner: PASS. Capability flags: executes scripts, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with detecting-oauth-token-theft?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is detecting-oauth-token-theft free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published detecting-oauth-token-theft?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.