Open Redirect Security Check (CWE-601)
SkillSecurityDetects redirects to user-controlled URLs that enable phishing and OAuth
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Open Redirect Security Check (CWE-601) skill
What this skill tells your AI
The instructions your AI receives, as published by thejefflarson/soundcheck in .claude/skills/open-redirect/SKILL.md and read by ahel’s review.
What this checks
Protects against open redirect vulnerabilities where an attacker crafts a link that redirects users from a trusted domain to a malicious site. Used in phishing campaigns to make malicious links appear legitimate, and in OAuth flows to steal authorization codes.
Vulnerable patterns
- Redirect target read directly from a query parameter, form field, or request body and passed unchanged to the framework's redirect API.
- Client-side navigation (
window.locationand equivalents) assigned a value derived from the URL or form input with no validation. - "Return to" or "next" parameters on login flows that accept any URL without an allowlist check.
- Validation that uses prefix or substring matching against the allowed host —
allowed.com.evil.compasses a naive prefix check.
Fix immediately
Flag the vulnerable code and explain the risk. Then suggest a fix that establishes these properties. Translate each property into the audited file's language and HTTP framework — use that framework's documented URL-parsing and redirect APIs.
- Every redirect target is either a relative path or a member of an exact host allowlist. Parse the URL, inspect the host component, and reject anything outside the allowlist. Prefix matching is not sufficient.
- Scheme-relative URLs are blocked explicitly. A value starting with
//parses as a protocol-relative URL and redirects to whatever host follows. Checking only forhttp://andhttps://misses this. - OAuth and login "return-to" parameters go through the same validator as any other redirect target. These are the highest-value targets because they run in an authenticated context; a redirect here hands the attacker the post-login session or an authorization code.
- On validation failure, redirect to a safe default (home, dashboard) rather than echoing an error containing the malicious URL. Echoing it back gives attackers a reflected-XSS surface.
Verification
- Every redirect target derived from user input is validated as either a relative path or a member of an explicit host allowlist
- Scheme-relative URLs (starting with
//) are blocked — not just absolutehttp://andhttps://URLs - OAuth and login "return_to" parameters are validated before redirect
- Validation failure routes to a safe default target, not back to the attacker-supplied URL
References
- CWE-601 (URL Redirection to Untrusted Site)
Signals
- GitHub stars
- 20
- Last commit
- Jul 2026
Advanced
- Catalog kind
- skill
- Gateway key
open-redirect-thejefflarson- Source
- github.com/thejefflarson/soundcheck