competition-jwt-claim-confusion
Installation
SKILL.md
Competition JWT Claim Confusion
Use this skill only as a downstream specialization after $ctf-sandbox-orchestrator is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to $ctf-sandbox-orchestrator first.
Use this skill when the decisive bug is not just "there is a JWT," but how headers, claims, and key selection turn into accepted identity.
Reply in Simplified Chinese unless the user explicitly requests English.
Quick Start
- Split the token path into parse, key lookup, signature or decryption, claim validation, and final acceptance.
- Record header fields, claims, key source, issuer, audience, and role mapping before mutating anything.
- Separate possession of a token from the exact service that accepts it.
- Keep parser behavior, trust policy, and resulting app session or privilege in one chain.
- Reproduce the smallest token-to-acceptance flow that proves the decisive confusion.