skills/aeondave/malskill/jwt-tool/Gen Agent Trust Hub

jwt-tool

Warn

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to clone a third-party repository from https://github.com/ticarpi/jwt_tool and install dependencies using pip3 install -r requirements.txt. These resources originate from an external repository not associated with a pre-approved trusted organization.
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to execute the downloaded Python scripts (jwt_tool.py) with various flags. This represents a pattern where code is fetched from an external source and executed locally.
  • [DATA_EXFILTRATION]: The toolkit includes functionality to send forged tokens to external target URLs using the -t flag, combined with custom headers (-rh) and cookies (-rc). While documented for testing purposes, this represents a network operation capability to external domains.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external, untrusted data in the form of JWT tokens, creating an attack surface for indirect prompt injection.
  • Ingestion points: The agent accepts user-provided JWT tokens as the primary input for analysis and exploitation scripts.
  • Boundary markers: There are no explicit instructions or delimiters defined to ensure the agent treats the content of the token as data rather than instructions.
  • Capability inventory: The skill has the ability to execute shell commands (via python3), perform network requests (via the -t flag), and interact with the local file system (reading keys and wordlists).
  • Sanitization: The instructions do not specify any validation or sanitization of the token string before it is interpolated into shell commands.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — jwt-tool