Lightlines
Catalogue
Sign in
By yaklang

api-auth-and-jwt-abuse

yaklang

Find weak token trust and authentication boundaries.

API security testing

What it does

Guides testing of API authentication and JWT trust boundaries, including claims, headers, rate limits, and API keys.

When to use it

Use when testing APIs that rely on JWTs, bearer tokens, API keys, or weak request identity signals.

How to use it

It changes how the agent tests API authentication by focusing on token trust, claim misuse, header spoofing, and rate-limit bypass.


Access · 1

This skill

target APIs

Write

Sends crafted requests to APIs

What you need · 0

No setup requirements listed in the analysis.


About this skill

Visibility
Public
Repository
yaklang/hack-skills
Created
Oct 8, 2026
Updated
Oct 8, 2026
Files
1