jwt-attack

Fail

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands (curl, cut, base64) and inline Python scripts to automate authentication bypass attacks against remote targets.
  • [DATA_EXFILTRATION]: Facilitates the harvesting and unauthorized reuse of authentication tokens extracted from production logs, JavaScript source bundles, and Vite environment files.
  • [CREDENTIALS_UNSAFE]: Documentation contains hardcoded leaked cryptographic secrets and provides scripts to brute-force authentication signing keys using common wordlists.
  • [REMOTE_CODE_EXECUTION]: Includes attack payloads designed to exploit 'kid' header vulnerabilities to achieve Path Traversal and potential code execution on target servers, while using dynamic Python execution for token forgery.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 31, 2026, 04:47 PM
Security Audit — agent-trust-hub — jwt-attack