Skip to main content

jwt-auth-auditor

星标0
分支0
更新时间2026年7月19日 10:06

Audit a codebase's JWT, refresh token, session cookie, risk-based authentication, and OIDC implementation against RFC 8725, RFC 9700, OWASP cheat sheets, and NIST SP 800-63B-4, producing a tiered scorecard with evidence-backed findings and concrete fixes. Use when the user asks to audit, review, grade, or harden authentication, sessions, JWTs, refresh tokens, login flows, token storage, password reset, or OIDC integration. Make sure to use this skill whenever the user requests a security assessment of authentication or session code, even if they never say the word JWT.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

文件资源管理器
5 个文件
SKILL.md
readonly