JWT Tool Skill

Help with authorized JWT assessment using ticarpi/jwt_tool. Use this skill whenever the user mentions `jwt_tool`, wants commands for JWT decoding, verification, secret cracking, claim tampering, playbook scans, `alg:none`, key confusion, JWKS spoofing or inline JWK injection, raw-request mode with `-r`, or needs to test bearer-token trust with a real HTTP request. Make sure to use it when the user asks how to audit or exploit JWT handling with `jwt_tool`, even if they only describe the token, headers, cookies, or a captured request and do not explicitly ask for a skill.

m-sec-org cbc6d10 3 files · 15.2 KB Updated

File contents

m-sec-org/breachweave/tree/main/packages/core/src/config/skills/builtin/jwt-tool-skill commit cbc6d1007d

Frequently asked questions

npx skillmds@latest add m-sec-org/jwt-tool-skill