jwt-attack
Fail
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands (curl, cut, base64) and inline Python scripts to automate authentication bypass attacks against remote targets.
- [DATA_EXFILTRATION]: Facilitates the harvesting and unauthorized reuse of authentication tokens extracted from production logs, JavaScript source bundles, and Vite environment files.
- [CREDENTIALS_UNSAFE]: Documentation contains hardcoded leaked cryptographic secrets and provides scripts to brute-force authentication signing keys using common wordlists.
- [REMOTE_CODE_EXECUTION]: Includes attack payloads designed to exploit 'kid' header vulnerabilities to achieve Path Traversal and potential code execution on target servers, while using dynamic Python execution for token forgery.
Recommendations
- AI detected serious security threats
Audit Metadata