jwt-oauth-token-attacks

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using bash, openssl, and python3. These commands are used to decode tokens, generate cryptographic keys, and run pentesting tools like jwt_tool.py and hashcat.
  • [EXTERNAL_DOWNLOADS]: The skill assumes the presence of or requires downloading external tools and wordlists, such as jwt_tool.py and the rockyou.txt dictionary, which are common in security auditing but represent unverified external dependencies.
  • [DATA_EXFILTRATION]: The documentation references https://analytics.third-party.com/track as an example of where tokens might leak via Referer headers. This specific domain has been flagged by automated scanners as associated with botnet activity.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect injection by processing authentication tokens and cryptographic keys provided by users or external endpoints. These inputs are directly used in command-line arguments and script parameters.
  • Ingestion points: JWT tokens and PEM-formatted public keys provided during analysis.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat the token content as potentially malicious data.
  • Capability inventory: The skill utilizes shell execution (bash), cryptographic utilities (openssl), and network-based key fetching (jku injection testing).
  • Sanitization: The skill lacks validation steps for the structure or content of the tokens before they are processed by the underlying tools.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 02:15 PM
Security Audit — agent-trust-hub — jwt-oauth-token-attacks