jwt-oauth-token-attacks
Fail
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DATA_EXFILTRATION]: The file contains a reference to a URL (
https://analytics.third-party.com/track) that has been identified by automated security scans as a malicious endpoint associated with botnet activity. Although the URL is used within the text as an educational example to illustrate how authentication tokens can leak via HTTP Referer headers to external services, providing an active malicious domain in instructions poses a safety risk for users and automated systems. - [COMMAND_EXECUTION]: The skill includes specific command-line instructions for operating offensive security tools, including
jwt_tool,hashcat, andJohn the Ripper. These examples guide the user in performing cryptographic attacks, such as brute-forcing HMAC secrets and manipulating JWT headers for signature bypass. - [EXTERNAL_DOWNLOADS]: The playbook outlines methods for fetching malicious JSON Web Key Sets (JWKS) from external, attacker-controlled domains (e.g.,
https://attacker.com/malicious-jwks.json). This technique is described as a means to execute header injection attacks and bypass cryptographic verification in target applications.
Recommendations
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata