API Auth and JWT Abuse skill: what it does and how to install it
Tests API authentication boundaries for JWTs, bearer tokens and API keys, including claim trust, header spoofing and rate-limit bypasses.
Summary generated from the skill's documentation.
Install
$ npx skills add yaklang/hack-skills --skill api-auth-and-jwt-abuseRun it in a terminal. If your agent is already running, start a new session so it picks the skill up.
About this skill
What it does. Provides a testing playbook for API authentication boundaries. It inspects JWT headers and claims, checks issuer and audience trust, and suggests tests for algorithm confusion, key lookup and remote key fetching. It also covers hidden fields, batch requests and rate-limit bypasses using identity headers and request variants.
When to use it. For APIs that rely on JWTs, bearer tokens, API keys or weak request identity signals, especially when assessing claim misuse, header spoofing, mass assignment or batching.
History
Repo stars
2.4k
Tracking since . A chart appears once there are 7 days of data.
Stars are counted for the whole repository, which holds 10 skills.
Installs
3.5k
Tracking since . A chart appears once there are 7 days of data.
Installs via skills.sh
Similar skills
- Protected Vercel DeploymentsAccesses and tests Vercel deployments that sit behind Vercel Authentication, SSO or Deployment Protection.
- Vercel CLI with TokensDeploys and manages Vercel projects with token-based authentication instead of interactive login.
- Security Threat ModelWrites a threat model grounded in the repository: trust boundaries, assets, attacker capabilities and mitigations.