jwt-attacks

jwt-attacks is a skill for Claude Code from ByamB4/find-cve-agent. It costs 25 tokens per session (863 once invoked), scanned A, original, Apache-2.0.

A security review for weaknesses in JWTs, signed tokens commonly used to prove a user's identity between services.

In plain words
What is it for?
Use it to inspect code that creates or validates JWTs, including algorithm settings, signing secrets, key lookup, and embedded key data.
Why use it?
It helps identify token checks that attackers could manipulate to forge authentication or bypass verification.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the find-cve-agent plugin — 21 skills, 7 commands, 5 agents shipped together

Good fit Use it to inspect code that creates or validates JWTs, including algorithm settings, signing secrets, key lookup, and embedded key data.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/byamb4/find-cve-agent/jwt-attacks
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add ByamB4/find-cve-agent --skill jwt-attacks
Clone the repo
git clone --depth 1 https://github.com/ByamB4/find-cve-agent

Made for: Claude Code.

Or install find-cve-agent, the plugin that ships this one along with the rest of its 21 skills, 7 commands, 5 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for jwt-attacks

README.md
[![agentmods](https://agentmods.dev/badge/skills/byamb4/find-cve-agent/jwt-attacks.svg)](https://agentmods.dev/skills/byamb4/find-cve-agent/jwt-attacks)
Your own site
<a href="https://agentmods.dev/skills/byamb4/find-cve-agent/jwt-attacks"><img src="https://agentmods.dev/badge/skills/byamb4/find-cve-agent/jwt-attacks.svg" alt="Measured on agentmods" height="20"></a>
Per session 25 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 863 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00025 $0.00863
Opus 5 $0.00013 $0.00432
Sonnet 5 $0.00005 $0.00173
Haiku 4.5 $0.00003 $0.00086

Measured 8d ago against content hash 436bee101df9, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

jwt-attacks scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/jwt-attacks/SKILL.md · 115 lines

How it starts

The opening of the file, as written. The whole thing — 115 lines — stays where its author put it; the contents beside it link to each section on GitHub.

JWT Attack Detection

When to Use

Audit JWT verification/generation libraries, authentication implementations, and any code that validates or creates JSON Web Tokens.

Attack Types

1. Algorithm Confusion (RS256 to HS256)

The server uses RS256 (asymmetric) but the attacker changes the token header to HS256 (symmetric) and signs with the public key as the HMAC secret.

Conditions: Library accepts algorithm from token header without allowlist validation.

2. alg:none Bypass

Token header specifies "alg": "none", and the library accepts unsigned tokens.

Conditions: Library does not validate algorithm or allows "none".

3. JWK Header Injection

Attacker embeds their own public key in the token header via the jwk parameter, and the library uses it for verification.

4. Weak HMAC Secrets

HMAC secrets that are short, common words, or default values. Can be brute-forced offline.

5. kid (Key ID) Attacks

  • Path traversal: "kid": "../../dev/null" -- sign with empty key
  • SQL injection: "kid": "' UNION SELECT 'secret' --" -- inject known key
  • Command injection: "kid": "|id" -- if kid is passed to shell

6. jku/x5u URL Manipulation

jku (JWK Set URL) or x5u (X.509 URL) in header points to attacker-controlled server hosting a JWK Set with the attacker key.

Process

Step 1: Find JWT Usage

grep -rn "jwt\.verify\|jwt\.decode\|jwt\.sign\|jwt\.encode" .
grep -rn "jsonwebtoken\|jose\|PyJWT\|go-jose\|nimbus-jose" .
grep -rn "JWTVerify\|jwtVerify\|createRemoteJWKSet" .

Step 2: Check Algorithm Validation

grep -rn "algorithms\|algorithm.*=\|alg.*:" . | grep -i jwt

Is the algorithm explicitly specified or taken from the token header?

// VULNERABLE: no algorithm specified
jwt.verify(token, key);

// SAFE: algorithm allowlist
jwt.verify(token, key, { algorithms: ['RS256'] });

Step 3: Check for none Algorithm

grep -rn "none\|None\|NONE" . | grep -i "alg\|algorithm"

Read the full file on GitHub · 115 lines

Files

What ships with it

3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 115 lines · 25 tokens per session scan A 436bee101df9

Subscribe to this mod's changes

jwt-attacks is a skill published in the GitHub repository ByamB4/find-cve-agent (48 stars, last pushed 5mo ago), licensed Apache-2.0. It adds 25 tokens to every session and 863 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories