hunt-jwt-crypto

SKILLWorkflowcommunauté
v0.0.0elementalsoulsMITMis à jour il y a 1 moisSource →

Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g. an admin) without knowing a secret. Use when the app authenticates with a JSON Web Token (an `eyJ...` Bearer token in the Authorization header, a coo

Community-submitted skill. Not yet reviewed by the Forge team. Full prompt content may not be available.Request review →
4kÉtoiles du dépôt
1Clients
1Formats
il y a 1 moisDernière mise à jour
Skill
Auteurelementalsouls
Version0.0.0
LicenceMIT
CatégorieWorkflow
Formatsskill.md
PromptOuvrir (voir l’onglet Prompt)
Compatibilité
Claude✓ Pris en charge
Cursor—
Copilot—
ChatGPT—
Gemini—
À propos

Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g. an admin) without knowing a secret. Use when the app authenticates with a JSON Web Token (an `eyJ...` Bearer token in the Authorization header, a cookie, or a login response). This skill OWNS JWT signature/crypto forgery (alg:none, key confusion, ki

Mots-clés
skillclaude

Aucune couverture des dépendances

Cette entrée ne publie aucun paquet npm : Forge n'a donc pas d'arbre de dépendances pour elle. C'est une lacune de couverture — pas une affirmation qu'elle n'a aucune dépendance.

Thèmes

Apparentés dans crypto & web3