Skip to main content

jwt-auth-auditor

Stars0
Forks0
UpdatedJuly 19, 2026 at 10:06

Audit a codebase's JWT, refresh token, session cookie, risk-based authentication, and OIDC implementation against RFC 8725, RFC 9700, OWASP cheat sheets, and NIST SP 800-63B-4, producing a tiered scorecard with evidence-backed findings and concrete fixes. Use when the user asks to audit, review, grade, or harden authentication, sessions, JWTs, refresh tokens, login flows, token storage, password reset, or OIDC integration. Make sure to use this skill whenever the user requests a security assessment of authentication or session code, even if they never say the word JWT.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
5 files
SKILL.md
readonly