From cybersecurity-skills
Implement secure OAuth 2.0 flows: Authorization Code with PKCE, Client Credentials, and Device Grant. Covers token lifecycle, scope design, and OAuth 2.1 security requirements.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cybersecurity-skills:configuring-oauth2-authorization-flowThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Configure secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant. This skill covers flow selection, PKCE implementation, token lifecycle management, scope design, and alignment with OAuth 2.1 security requirements.
Configure secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant. This skill covers flow selection, PKCE implementation, token lifecycle management, scope design, and alignment with OAuth 2.1 security requirements.
PKCE (RFC 7636) prevents authorization code interception attacks:
code_verifier (43-128 characters, unreserved URI chars)code_challenge = BASE64URL(SHA256(code_verifier))code_challenge and code_challenge_method=S256code_verifierSHA256(code_verifier) matches stored code_challengeread:users, write:orders, admin:settings| Control | NIST 800-53 | Description |
|---|---|---|
| Access Control | AC-3 | Token-based access enforcement |
| Authentication | IA-5 | Client credential management |
| Session Management | SC-23 | Token lifecycle management |
| Audit | AU-3 | Log all token issuance and revocation |
| Cryptographic Protection | SC-13 | PKCE and token signing |
npx claudepluginhub costrict-plugins-repo/mukul975-anthropic-cybersecurity-skills-cybersecurity-skillsConfigures OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant. Covers flow selection, PKCE implementation, token lifecycle, and OAuth 2.1 security best practices.
Configures OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant. Covers flow selection, PKCE implementation, token lifecycle, and OAuth 2.1 security best practices.
Configures secure OAuth 2.0 authorization flows: Authorization Code with PKCE, Client Credentials, Device Grant. Covers PKCE implementation, token lifecycle, scopes, and OAuth 2.1 best practices for IAM.