Find exploitable weaknesses in token trust and OAuth flows.
web application security
Guides testing of JWT trust, signing, key handling, claims, bearer flows, and OAuth account binding.
When to use it
Use when validating token trust, signing algorithms, key handling, claim abuse, bearer flows, or OAuth account binding.
It changes how the agent tests token-centric attacks and OAuth flow abuse.
This skill
target web application
Tests crafted authentication requests
attacker.com
Hosts a malicious JWKS
target key endpoints
Reads target key endpoints
/usr/share/wordlists/rockyou.txt
Reads the rockyou wordlist
Routes redirect URI, state, nonce, PKCE, and account-binding validation to this skill.
Routes cross-origin browser-readable API and token-leakage testing to this skill when applicable.
Routes testing of enterprise SSO outside OAuth or OIDC to this skill.