jwt-tool
Warn
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to clone a third-party repository from
https://github.com/ticarpi/jwt_tooland install dependencies usingpip3 install -r requirements.txt. These resources originate from an external repository not associated with a pre-approved trusted organization. - [REMOTE_CODE_EXECUTION]: The skill provides instructions to execute the downloaded Python scripts (
jwt_tool.py) with various flags. This represents a pattern where code is fetched from an external source and executed locally. - [DATA_EXFILTRATION]: The toolkit includes functionality to send forged tokens to external target URLs using the
-tflag, combined with custom headers (-rh) and cookies (-rc). While documented for testing purposes, this represents a network operation capability to external domains. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external, untrusted data in the form of JWT tokens, creating an attack surface for indirect prompt injection.
- Ingestion points: The agent accepts user-provided JWT tokens as the primary input for analysis and exploitation scripts.
- Boundary markers: There are no explicit instructions or delimiters defined to ensure the agent treats the content of the token as data rather than instructions.
- Capability inventory: The skill has the ability to execute shell commands (via
python3), perform network requests (via the-tflag), and interact with the local file system (reading keys and wordlists). - Sanitization: The instructions do not specify any validation or sanitization of the token string before it is interpolated into shell commands.
Audit Metadata