adobe-express-oauth-authentication — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited adobe-express-oauth-authentication (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill guides you through OAuth 2.0 implementation for add-ons, focusing on PKCE flow, token lifecycle, and secure credential storage.
OAuth 2.0 with PKCE (Proof Key for Code Exchange) is the standard for add-ons:
{
"permissions": {
"oauth": [
"www.dropbox.com",
"login.microsoftonline.com",
"accounts.google.com"
]
}
}Only list providers your add-on actually uses.
addOnUISdk.app.oauth.authorize()?"Use OAuthUtils.js helper (from code samples):
Call addOnUISdk.app.oauth.authorize() with:
authorizationUrl (provider-specific)clientId (your app registration)codeChallenge (from PKCE)scope (request minimal scopes needed)After user authorizes, exchange:
With provider's token endpoint.
await addOnUISdk.instance.clientStorage.setItem("oauth_token", token);Client Storage is encrypted and persists across sessions.
Monitor token expiry. Refresh using refresh token:
See references/oauth-implementation.md for:
Pass to other skills when:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.