Audit a codebase's JWT, refresh token, session cookie, risk-based authentication, and OIDC implementation against RFC 8725, RFC 9700, OWASP cheat sheets, and NIST SP 800-63B-4, producing a tiered scorecard with evidence-backed findings and concrete fixes. Use when the user asks to audit, review, grade, or harden authentication, sessions, JWTs, refresh tokens, login flows, token storage, password reset, or OIDC integration. Make sure to use this skill whenever the user requests a security assessment of authentication or session code, even if they never say the word JWT.
2026-07-19