Detect insecure JWT implementations

sast-jwtskillsetup L30
reasonless-throne486/sast-skills
What it does

Detect JWT vulnerabilities in code

Best for

Finding JWT signature bypass, algorithm confusion, and key exposure in token handling

Inputs
  • · Codebase under analysis
  • · sast/architecture.md (prerequisite)
Outputs
  • · sast/jwt-results.md with findings
  • · JWT parsing, validation, and signing issues
Preconditions
  • · sast/architecture.md must exist
  • · Source code accessible
Failure modes
  • · Custom JWT parsing misses validation edge cases
  • · Timing attacks not caught by static analysis
  • · Key rotation issues missed
Trust signals
  • · Three-phase analysis of JWT creation, validation, and use
  • · Covers algorithm confusion, signature bypass
  • · Identifies key storage issues