Agent skill

Identity Federation

by sickn33 in sickn33/agentic-awesome-skills

Authorized assessment of federated identity systems: SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token-confusion issues.

MITAuto-check passedBackend & APIs

Install Identity Federation

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill identity-federation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills identity-federation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/identity-federation .claude/skills/identity-federation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
identity-federation
GitHub stars
47k
Used in
1 other repo
Token cost
~617 tokens
SKILL.md length
236 words
Files
2 (incl. references)
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

Authorized assessment of federated identity systems: SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token-confusion issues.

  • Tasks that involve OAuth and OpenID Connect
  • SKILL.md covers When to Use, 适用场景, 工作流 and 工具链, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Authentication

What it does

Identity Federation is an agent skill from sickn33/agentic-awesome-skills. Authorized assessment of federated identity systems: SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token-confusion issues.

Its SKILL.md is about 620 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/sso-flow-checklist.md`).

It sits in Backend & APIs, covering OAuth and OpenID Connect and Authentication. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve OAuth and OpenID Connect
  • Tasks that involve Authentication

Example prompts

  • “/identity-federation”

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Identity Federation loads about 617 tokens when it runs, and up to ~677 if it reads all its reference files. Until then it costs about 37 tokens; SKILL.md has 236 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~617
With references · SKILL.md plus every file in references/, read only if the agent opens them
~677

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 236 words, ~617 tokens.

Download SKILL.mdSave it as .claude/skills/identity-federation/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
identity-federation
description
Authorized assessment of federated identity systems: SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token-confusion issues.
risk
offensive
source
https://github.com/zhaoxuya520/reverse-skill
source_repo
zhaoxuya520/reverse-skill
source_type
community
date_added
2026-08-25
license
MIT
license_source
https://github.com/zhaoxuya520/reverse-skill/blob/main/LICENSE

⚠️ AUTHORIZED USE ONLY This skill is for educational purposes or authorized security assessments only. You must have explicit, written permission from the system owner before using this tool. Misuse of this tool is illegal and strictly prohibited.

Mandatory confirmation gate Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:

  1. Ask the user to state the exact target URL, IP, account, or resource.
  2. Ask the user to confirm written authorization and the permitted scope.
  3. Show the exact command(s) and explain their expected effect.
  4. Wait for explicit confirmation in the current conversation.

Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.

Identity Federation (SAML / OIDC / OAuth)

When to Use

  • Testing SSO/federation flows within an approved scope.
  • Hunting signature-validation or audience-confusion flaws.

适用场景

  • SAML Response 签名/断言篡改面(经典缺陷模式)
  • OIDC 隐式/授权码 + PKCE 缺失
  • redirect_uri / state / nonce 问题
  • IdP 与 SP 元数据、多租户 issuer 混淆
  • 与 api-security JWT 攻击互补(本 skill 偏联邦与 SSO 流)

工作流

text
□ 画清:User → SP → IdP → Token → SP
□ 收集:/.well-known/openid-configuration、SAML metadata
□ 检查:redirect_uri 精确匹配、state 绑定、PKCE
□ 检查:SAML 签名覆盖范围、algorithm 降级
□ 会话固定与登出失效

工具链

工具用途
Burp + SAML Raider 等断言编辑(授权)
jwt_toolJWT 段
浏览器 DevTools重定向链
IdP 管理日志审计

参考

  • references/sso-flow-checklist.md
  • ../api-security/ ../windows-ad/(企业 IdP)

路由上下文

上游: MASTER R37
下游: 纯 API JWT → api-security;云 IdP → cloud-k8s

任务完成自检

  • 是否映射完整 SSO 流?
  • 每个 Finding 是否有复现与影响?
  • Checklist?

Limitations

  • IdP-side testing is often out of scope; confirm boundaries first.
  • Token replay tests can lock out real users; stage carefully.

Adapted from zhaoxuya520/reverse-skill (MIT).

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/identity-federation of sickn33/agentic-awesome-skills.

  • SKILL.md
  • references/sso-flow-checklist.md

Open the folder on GitHubat commit b84d35a

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Identity Federation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Identity Federation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Identity Federation this skillsickn33/agentic-awesome-skills47k1 repos~617Automated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT
OAuth Account Setupspinabot/brigade11k—~878Automated safety check: PassMIT
Auth Implementation Patternsynulihao/AgentSkillOS61810 repos~4.4kAutomated safety check: PassNone

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • OAuth Account Setup

    spinabot/brigade

    Connects an OAuth 2.0 account such as Gmail with the built-in oauth_authorize tool: an authorization link, automatic code capture and sealed token storage.

    11k GitHub stars~878 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    618 GitHub starsUsed in 10 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Socialite Development

    hexlet-volunteers/hexlet-sicp

    Manages OAuth social authentication with Laravel Socialite. An agent skill from hexlet-volunteers/hexlet-sicp.

    114 GitHub starsUsed in 5 repos~1.2k tokens
    Backend & APIsAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Identity Federation

What does Identity Federation do?

Authorized assessment of federated identity systems: SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token-confusion issues. Identity Federation is an agent skill from sickn33/agentic-awesome-skills. Authorized assessment of federated identity systems: SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token-confusion issues.

When should I use Identity Federation?

Identity Federation fits situations like: tasks that involve OAuth and OpenID Connect; tasks that involve Authentication.

How do I install Identity Federation in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill identity-federation -a claude-code`. Or copy the skill folder (skills/identity-federation in sickn33/agentic-awesome-skills) into .claude/skills/identity-federation in your project. Claude Code loads it when a task matches its description.

How do I install Identity Federation in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill identity-federation -a codex`. Or copy the skill folder (skills/identity-federation in sickn33/agentic-awesome-skills) into .agents/skills/identity-federation in your project. Codex loads it when a task matches its description.

Can I use Identity Federation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill identity-federation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/identity-federation, .gemini/skills/identity-federation, .github/skills/identity-federation and .opencode/skills/identity-federation in your project.

What does Identity Federation need to run?

SKILL.md names no scripts, command-line tools or credentials: Identity Federation is instructions for the agent only.

Does Identity Federation access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Identity Federation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Identity Federation use?

Identity Federation is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Identity Federation use?

About 617 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 60 tokens, read only when the agent opens those files.

What are the alternatives to Identity Federation?

Skills that share tags, products or a category with Identity Federation: Fortify Development (coollabsio/coolify, 63k stars), Cognito (itsmostafa/aws-agent-skills, 1.2k stars), Security Review (doorkeeper-gem/doorkeeper, 5.5k stars) and OAuth Account Setup (spinabot/brigade, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Identity Federation?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.