Skip to main content
jwt-oauth-token-attacksby yaklang.io ProjectDevelopmentGitHub stars: 2.4k

JWT and OAuth Token Attacks skill: what it does and how to install it

Tests JWT and OAuth 2.0 token security for signing flaws, claim abuse, bearer-token leakage and account-binding weaknesses.

Summary generated from the skill's documentation.

Warning. A security audit flagged this skill with a critical risk warning. Read its SKILL.md and scripts before you install it.

Install

$ npx skills add yaklang/hack-skills --skill jwt-oauth-token-attacks

Run it in a terminal. If your agent is already running, start a new session so it picks the skill up.

About this skill

What it does. Guides security testing of JWTs and OAuth 2.0 flows by decoding tokens, checking signing algorithms and key handling, and probing claims, kid, jku, redirect URIs, state, PKCE, scopes and token leakage. It includes command-line examples and checklists for identifying forgery, replay and account-binding issues.

When to use it. Applies to token-centric authentication testing in web applications, including bearer flows and OAuth integrations. Route broader redirect, nonce or enterprise SSO configuration checks to the related OAuth/OIDC or SAML guidance.

History

Repo stars

2.4k

Tracking since . A chart appears once there are 7 days of data.

Stars are counted for the whole repository, which holds 10 skills.

Installs

3.5k

Tracking since . A chart appears once there are 7 days of data.

Installs via skills.sh

Similar skills