Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,14 +1,10 @@
---
name: testing-oauth2-implementation-flaws
description: 'Tests OAuth 2.0 and OpenID Connect implementations for security flaws
including authorization code interception, redirect URI manipulation, CSRF in OAuth
flows, token leakage, scope escalation, and PKCE bypass. The tester evaluates the
authorization server, client application, and token handling for common misconfigurations
that enable account takeover or unauthorized access. Activates for requests involving
OAuth security testing, OIDC vulnerability assessment, OAuth2 redirect bypass, or
authorization code flow testing.
'
description: Tests OAuth 2.0 and OpenID Connect implementations for authorization code
interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope
escalation, and PKCE bypass, using Burp Suite Professional and the EsPReSSO extension
to probe the authorization server, client, and token handling. Use when assessing OAuth2/OIDC
flows or SSO systems for misconfigurations enabling account takeover.
domain: cybersecurity
subdomain: api-security
tags: