GCP OAuth app abuse TL;DR: OAuth scopes for installed apps, consent screens as a phishing layer, marketplace surface. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References TODO