jwt-oauth-token-attacks
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using
bash,openssl, andpython3. These commands are used to decode tokens, generate cryptographic keys, and run pentesting tools likejwt_tool.pyandhashcat. - [EXTERNAL_DOWNLOADS]: The skill assumes the presence of or requires downloading external tools and wordlists, such as
jwt_tool.pyand therockyou.txtdictionary, which are common in security auditing but represent unverified external dependencies. - [DATA_EXFILTRATION]: The documentation references
https://analytics.third-party.com/trackas an example of where tokens might leak via Referer headers. This specific domain has been flagged by automated scanners as associated with botnet activity. - [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect injection by processing authentication tokens and cryptographic keys provided by users or external endpoints. These inputs are directly used in command-line arguments and script parameters.
- Ingestion points: JWT tokens and PEM-formatted public keys provided during analysis.
- Boundary markers: No explicit delimiters or instructions are provided to the agent to treat the token content as potentially malicious data.
- Capability inventory: The skill utilizes shell execution (
bash), cryptographic utilities (openssl), and network-based key fetching (jkuinjection testing). - Sanitization: The skill lacks validation steps for the structure or content of the tokens before they are processed by the underlying tools.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata