Skip to main content
Manusで任意のスキルを実行
ワンクリックで

jwt-hunter

スター15
フォーク7
更新日2026年6月28日 16:46

Tests JSON Web Tokens for `alg: none` acceptance, missing signature validation, HS256 secret cracking, RS256-to-HS256 algorithm confusion, claim tampering (role/uid escalation), post-logout / post-password-change token validity, and `kid` / `jku` / `x5u` injection. Use when the target uses JWTs for auth (strings starting with `ey` in Authorization headers, cookies, or bodies); when issued tokens contain cleartext roles or identifiers; or when tokens persist after logout. Produces findings with CWE-327 / CWE-347 / CWE-287 mapping, tampered-token PoCs, and library-configuration remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.

インストール

Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。

ファイルエクスプローラー
4 ファイル
SKILL.md
readonly