Agent skill

API Auth And JWT Abuse

by yaklang in yaklang/hack-skills

API authentication and JWT abuse playbook. An agent skill from yaklang/hack-skills.

MITAuto-check passedBackend & APIs

Install API Auth And JWT Abuse

skills CLI
$ npx skills add yaklang/hack-skills --skill api-auth-and-jwt-abuse -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yaklang/hack-skills api-auth-and-jwt-abuse --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/api-auth-and-jwt-abuse .claude/skills/api-auth-and-jwt-abuse && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-auth-and-jwt-abuse
GitHub stars
2.4k
Token cost
~567 tokens
SKILL.md length
223 words
Files
1
Skills in repo
27
Repo updated
First seen
Licence
MIT

At a glance

API authentication and JWT abuse playbook. An agent skill from yaklang/hack-skills.

  • Works in 5 steps: TOKEN TRIAGE → QUICK ATTACK PICKS → HIDDEN FIELDS AND BATCH ABUSE → …
  • Testing bearer tokens
  • SKILL.md covers 1. TOKEN TRIAGE, 2. QUICK ATTACK PICKS, 3. HIDDEN FIELDS AND BATCH ABUSE and 4. RATE LIMIT BYPASS FAMILIES, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

API Auth And JWT Abuse is an agent skill from yaklang/hack-skills. API authentication and JWT abuse playbook. Use when testing bearer tokens, API keys, claim trust, header spoofing, rate limits, and API auth boundary weaknesses.

Its SKILL.md is about 570 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication and Rate limiting. It works with GraphQL. The repository describes itself as: Helping AI Agent become an awesome practical hacker! The licence is MIT.

When your agent uses it

  • Testing bearer tokens
  • Header spoofing
  • API auth boundary weaknesses

Example prompts

  • “/api-auth-and-jwt-abuse”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. TOKEN TRIAGE
  2. QUICK ATTACK PICKS
  3. HIDDEN FIELDS AND BATCH ABUSE
  4. RATE LIMIT BYPASS FAMILIES
  5. NEXT ROUTING

What it can do on your machine

Read from SKILL.md and the folder at commit 6fbf0bc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Auth And JWT Abuse loads about 567 tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 223 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~567

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yaklang/hack-skills at commit 6fbf0bc, republished under its MIT licence (© yaklang). 223 words, ~567 tokens.

Download SKILL.mdSave it as .claude/skills/api-auth-and-jwt-abuse/SKILL.md (or your agent's skills folder).
name
api-auth-and-jwt-abuse
description
API authentication and JWT abuse playbook. Use when testing bearer tokens, API keys, claim trust, header spoofing, rate limits, and API auth boundary weaknesses.

SKILL: API Auth and JWT Abuse — Token Trust, Header Tricks, and Rate Limits

AI LOAD INSTRUCTION: Use this skill when APIs rely on JWT, bearer tokens, API keys, or weak request identity signals. Focus on token trust boundaries, claim misuse, header spoofing, and rate-limit bypass.

1. TOKEN TRIAGE

Inspect:

  • alg, kid, jku, x5u
  • role, org, tenant, scope, or privilege claims
  • issuer and audience mismatches
  • reuse of mobile and web tokens across products

2. QUICK ATTACK PICKS

PatternFirst Test
alg:none acceptanceunsigned token with trailing dot
RS256 confusionswitch to HS256 using public key as secret
kid lookup trustpath traversal or injection in kid
remote key fetch trustattacker-controlled jku or x5u
weak secretoffline crack with targeted wordlists

3. HIDDEN FIELDS AND BATCH ABUSE

Mass assignment field picks
text
role
isAdmin
admin
verified
plan
tier
permissions
org
owner
Rate limit and batch abuse picks
text
X-Forwarded-For: 1.2.3.4
X-Real-IP: 5.6.7.8
Forwarded: for=9.9.9.9

GraphQL or JSON batch abuse candidates:

  • arrays of login mutations
  • bulk object fetches with varying IDs
  • repeated password reset or verification calls in one request

4. RATE LIMIT BYPASS FAMILIES

text
X-Forwarded-For
X-Real-IP
Forwarded
User-Agent rotation
Path case / slash variants

5. NEXT ROUTING

© yaklang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/api-auth-and-jwt-abuse of yaklang/hack-skills.

Open the folder on GitHubat commit 6fbf0bc

Compare with similar skills

API Auth And JWT Abuse next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Auth And JWT Abuse compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Auth And JWT Abuse this skillyaklang/hack-skills2.4k—~567Automated safety check: PassMIT
API Auditbriiirussell/cybersecurity-skills413—~2.8kAutomated safety check: NotesMIT
Domain Webfjrevoredo/mini-diarium3091 repos~1kAutomated safety check: PassMIT
Discover APIrand/cc-polymath181—~1.5kAutomated safety check: PassMIT
API Connector Builderericrisco/rsc-harness180—~3.6kAutomated safety check: PassMIT
Hunt APIEncod3d-Sec/TORCH329—~1.9kAutomated safety check: PassMIT

Similar skills

  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Domain Web

    fjrevoredo/mini-diarium

    A skill your agent uses when building web services. An agent skill from fjrevoredo/mini-diarium.

    309 GitHub starsUsed in 1 repo~1k tokens
    Backend & APIsAuto-check passed
  • Discover API

    rand/cc-polymath

    Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.

    181 GitHub stars~1.5k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • API Connector Builder

    ericrisco/rsc-harness

    A skill your agent uses when writing a client for someone else's REST or GraphQL API: auth flow choice and token refresh, pagination to exhaustion, retry-with-jitter on transient failures only…

    180 GitHub stars~3.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Hunt API

    Encod3d-Sec/TORCH

    API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse.

    329 GitHub stars~1.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Linear Common Errors

    jeremylongshore/tons-of-skills-marketplace

    Diagnose Linear GraphQL and SDK failures from transport, response, and request evidence.

    2.8k GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed

More from yaklang/hack-skills

All 27 skills in this repo
  • Anti Debugging Techniques

    yaklang/hack-skills

    Anti-debugging detection and bypass playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~3.4k tokensUpdated 27 days ago
    Auto-check passed
  • API Authorization And Bola

    yaklang/hack-skills

    API authorization and BOLA testing playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~449 tokensUpdated 27 days ago
    Auto-check passed
  • API Recon And Docs

    yaklang/hack-skills

    API reconnaissance and documentation review playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~456 tokensUpdated 27 days ago
    Auto-check passed
  • Attack Surface Mapping

    yaklang/hack-skills

    Draw a testable attack surface from one authorized target URL or one application.

    2.4k GitHub stars~2.6k tokensUpdated 27 days ago
    Auto-check passed
  • Classical Cipher Analysis

    yaklang/hack-skills

    Classical cipher analysis playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~4.8k tokensUpdated 27 days ago
    Auto-check passed
  • Code obfuscation analysis and deobfuscation playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~3.3k tokensUpdated 27 days ago
    Auto-check passed

Works with

Categories

Questions about API Auth And JWT Abuse

What does API Auth And JWT Abuse do?

API authentication and JWT abuse playbook. An agent skill from yaklang/hack-skills. API Auth And JWT Abuse is an agent skill from yaklang/hack-skills. API authentication and JWT abuse playbook.

When should I use API Auth And JWT Abuse?

API Auth And JWT Abuse fits situations like: testing bearer tokens; header spoofing; API auth boundary weaknesses.

How do I install API Auth And JWT Abuse in Claude Code?

Run `npx skills add yaklang/hack-skills --skill api-auth-and-jwt-abuse -a claude-code`. Or copy the skill folder (skills/api-auth-and-jwt-abuse in yaklang/hack-skills) into .claude/skills/api-auth-and-jwt-abuse in your project. Claude Code loads it when a task matches its description.

How do I install API Auth And JWT Abuse in Codex?

Run `npx skills add yaklang/hack-skills --skill api-auth-and-jwt-abuse -a codex`. Or copy the skill folder (skills/api-auth-and-jwt-abuse in yaklang/hack-skills) into .agents/skills/api-auth-and-jwt-abuse in your project. Codex loads it when a task matches its description.

Can I use API Auth And JWT Abuse in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaklang/hack-skills --skill api-auth-and-jwt-abuse -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-auth-and-jwt-abuse, .gemini/skills/api-auth-and-jwt-abuse, .github/skills/api-auth-and-jwt-abuse and .opencode/skills/api-auth-and-jwt-abuse in your project.

What does API Auth And JWT Abuse need to run?

SKILL.md names no scripts, command-line tools or credentials: API Auth And JWT Abuse is instructions for the agent only.

Does API Auth And JWT Abuse access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Auth And JWT Abuse safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Auth And JWT Abuse use?

API Auth And JWT Abuse is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Auth And JWT Abuse use?

About 567 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Auth And JWT Abuse?

Skills that share tags, products or a category with API Auth And JWT Abuse: API Audit (briiirussell/cybersecurity-skills, 413 stars), Domain Web (fjrevoredo/mini-diarium, 309 stars), Discover API (rand/cc-polymath, 181 stars) and API Connector Builder (ericrisco/rsc-harness, 180 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Auth And JWT Abuse?

yaklang (a GitHub organization) maintains it in yaklang/hack-skills, which has 2,418 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on September 13, 2026.

Source: yaklang/hack-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.