Skip to content
appsgit

Browser Auth Flow

Browser Auth Flow is an agent skill (a SKILL.md file) from ruvnet/ruflo. Probe a site's authentication flow for redirect leaks, missing CSRF, weak session cookies, and OAuth misconfiguration; produces an auth findings.md. It works with Claude Code and Codex and has 74,016 GitHub stars across a repository of 7 listed skills.

github.com/ruvnet/ruflo/plugins/ruflo-browser/skills/browser-auth-flow (opens in a new tab)

  • Multi-skill repo
  • Plugin marketplace
  • Security
  • Actively maintained

Add this skill

Claude

This repository is a Claude Code plugin marketplace. In Claude Code:

/plugin marketplace add ruvnet/ruflo
/plugin install ruflo-browser@ruflo

In the Claude apps, zip the browser-auth-flow folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

ChatGPT / Codex

Codex reads skills from .agents/skills/ in a repo or ~/.agents/skills/ for every project:

git clone --depth 1 https://github.com/ruvnet/ruflo.git
cp -r ruflo/plugins/ruflo-browser/skills/browser-auth-flow .agents/skills/browser-auth-flow   # repo; ~/.agents/skills for all projects

Standalone skills also load in the ChatGPT desktop app.

Cursor

Cursor loads skills from .cursor/skills/ (or ~/.cursor/skills/) and also reads .claude/skills/:

git clone --depth 1 https://github.com/ruvnet/ruflo.git
cp -r ruflo/plugins/ruflo-browser/skills/browser-auth-flow .cursor/skills/browser-auth-flow   # project; ~/.cursor/skills for all projects

Source (checked Oct 7, 2026): code.claude.com/docs/en/skills (opens in a new tab), code.claude.com/docs/en/plugin-marketplaces (opens in a new tab), support.claude.com/en/articles/12512180-using-skills-in-claude (opens in a new tab), learn.chatgpt.com/docs/build-skills (opens in a new tab), cursor.com/docs/context/skills (opens in a new tab)

What this skill does

Probe a site's authentication flow for redirect leaks, missing CSRF, weak session cookies, and OAuth misconfiguration; produces an auth findings.md Adversarial probe of a site's authentication. Drives the login flow once, records the trajectory, then runs a configurable set of probes against the captured artifacts and live page. Output is a structured findings.md inside the RVF container.

More skills in ruvnet/ruflo

7 skills are listed from this repository.

FAQ

Browser Auth Flow FAQ

Still curious? Email info@appsgit.com.

What is the Browser Auth Flow skill?

Browser Auth Flow is an agent skill (a SKILL.md file) from ruvnet/ruflo. Probe a site's authentication flow for redirect leaks, missing CSRF, weak session cookies, and OAuth misconfiguration; produces an auth findings.md. It works with Claude Code and Codex and has 74,016 GitHub stars across a repository of 7 listed skills. Its SKILL.md lives at github.com/ruvnet/ruflo/plugins/ruflo-browser/skills/browser-auth-flow.

How do I install the Browser Auth Flow skill?

In Claude Code, run /plugin marketplace add ruvnet/ruflo and then /plugin install ruflo-browser@ruflo. For Codex or Cursor, copy the browser-auth-flow folder into .agents/skills/ or .cursor/skills/.

Is the Browser Auth Flow skill free?

Yes. The repository is open source under the MIT license.

Is Browser Auth Flow maintained?

The repository's most recent commit was on Oct 7, 2026. Its latest release is v3.54.0. appsgit only lists skills from repositories with a commit in the last six months.