hunt-jwt-crypto

SKILLWorkflowCommunity
v0.0.0elementalsoulsMITAktualisiert vor 1 Mon.Quelle →

Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g. an admin) without knowing a secret. Use when the app authenticates with a JSON Web Token (an `eyJ...` Bearer token in the Authorization header, a coo

Community-submitted skill. Not yet reviewed by the Forge team. Full prompt content may not be available.Request review →
4kRepo-Sterne
1Clients
1Formate
vor 1 Mon.Letzte Aktualisierung
Skill
Autorelementalsouls
Version0.0.0
LizenzMIT
KategorieWorkflow
Formateskill.md
PromptÖffnen (siehe Tab „Prompt“)
Kompatibilität
Claude✓ Unterstützt
Cursor—
Copilot—
ChatGPT—
Gemini—
Über

Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g. an admin) without knowing a secret. Use when the app authenticates with a JSON Web Token (an `eyJ...` Bearer token in the Authorization header, a cookie, or a login response). This skill OWNS JWT signature/crypto forgery (alg:none, key confusion, ki

Schlagwörter
skillclaude

Keine Abdeckung der Abhängigkeiten

Dieser Eintrag veröffentlicht kein npm-Paket, daher hat Forge keinen Abhängigkeitsbaum dafür. Das ist eine Lücke in der Abdeckung — keine Aussage, dass er keine Abhängigkeiten hat.

Themen

Verwandtes in crypto & web3