
from Anthropic Cybersecurity Skills9
Identify and exploit critical JWT vulnerabilities including algorithm confusion, 'none' bypass, and weak secret exploitation.
This skill provides a comprehensive framework for security agents to audit and test JSON Web Token (JWT) implementations. It focuses on breaking authentication and authorization by exploiting common misconfigurations in JWT libraries and server-side verification logic.
Use this skill during API security assessments, penetration tests of SSO systems, or when evaluating OAuth 2.0 and OpenID Connect implementations where JWTs are used for session management.
jwt_tool for automation.Designed for security-focused agents with terminal access (bash/python) and common security tools like Burp Suite and Hashcat.
This skill has not been reviewed by our automated audit pipeline yet.
API BOLA/IDOR Security Testing
Comprehensive guide for testing REST and GraphQL APIs for Broken Object Level Authorization (BOLA) and IDOR vulnerabilities.
SailPoint Identity Governance Implementation
Deploy and configure SailPoint IdentityNow or IdentityIQ for enterprise identity governance, lifecycle management, and compliance reporting.