Lightlines
Catalogue
Sign in
By yaklang

jwt-oauth-token-attacks

yaklang

Find exploitable weaknesses in token trust and OAuth flows.

web application security

What it does

Guides testing of JWT trust, signing, key handling, claims, bearer flows, and OAuth account binding.

When to use it

Use when validating token trust, signing algorithms, key handling, claim abuse, bearer flows, or OAuth account binding.

How to use it

It changes how the agent tests token-centric attacks and OAuth flow abuse.


Access · 4

This skill

target web application

Write

Tests crafted authentication requests

attacker.com

Write

Hosts a malicious JWKS

target key endpoints

Read

Reads target key endpoints

/usr/share/wordlists/rockyou.txt

Read

Reads the rockyou wordlist

What you need · 3

Routes redirect URI, state, nonce, PKCE, and account-binding validation to this skill.

Routes cross-origin browser-readable API and token-leakage testing to this skill when applicable.

Routes testing of enterprise SSO outside OAuth or OIDC to this skill.


About this skill

Visibility
Public
Repository
yaklang/hack-skills
Created
Oct 8, 2026
Updated
Oct 8, 2026
Files
1