Skip to main content
api-auth-and-jwt-abuseby yaklang.io ProjectDevelopmentGitHub stars: 2.4k

API Auth and JWT Abuse skill: what it does and how to install it

Tests API authentication boundaries for JWTs, bearer tokens and API keys, including claim trust, header spoofing and rate-limit bypasses.

Summary generated from the skill's documentation.

Install

$ npx skills add yaklang/hack-skills --skill api-auth-and-jwt-abuse

Run it in a terminal. If your agent is already running, start a new session so it picks the skill up.

About this skill

What it does. Provides a testing playbook for API authentication boundaries. It inspects JWT headers and claims, checks issuer and audience trust, and suggests tests for algorithm confusion, key lookup and remote key fetching. It also covers hidden fields, batch requests and rate-limit bypasses using identity headers and request variants.

When to use it. For APIs that rely on JWTs, bearer tokens, API keys or weak request identity signals, especially when assessing claim misuse, header spoofing, mass assignment or batching.

History

Repo stars

2.4k

Tracking since . A chart appears once there are 7 days of data.

Stars are counted for the whole repository, which holds 10 skills.

Installs

3.5k

Tracking since . A chart appears once there are 7 days of data.

Installs via skills.sh

Similar skills