offensive-jwt
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides educational content and technical checklists for security audits. The commands and code snippets included are documentation of attack methodologies intended for use by a penetration tester on authorized targets.
- [COMMAND_EXECUTION]: Includes example shell commands for adb, idevicebackup2, and curl to illustrate how to inspect mobile application storage and interact with APIs during a security assessment.
- [DYNAMIC_EXECUTION]: Contains a Python script snippet using the requests library to demonstrate timing attacks against HMAC comparisons. This serves as a conceptual proof-of-concept for auditors.
- [EXTERNAL_DOWNLOADS]: References established security tools and resources, such as jwt_tool on GitHub and the jwt.io debugging platform, which are standard utilities in the security industry.
Audit Metadata