Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,14 +1,11 @@
---
name: exploiting-jwt-algorithm-confusion-attack
description: 'Exploits JWT algorithm confusion vulnerabilities where the server''s
token verification library accepts the algorithm specified in the JWT header rather
than enforcing a fixed algorithm. The tester manipulates the alg header to switch
from RS256 to HS256 (using the RSA public key as the HMAC secret), sets alg to none
to bypass signature verification, or exploits kid/jku/x5u header injection to supply
attacker-controlled keys. Activates for requests involving JWT algorithm confusion,
alg none attack, key confusion attack, or JWT signature bypass.
'
description: >-
Exploits JWT algorithm confusion where the server's verification library trusts
the alg named in the token header, by switching RS256 to HS256 (signing with the
RSA public key as HMAC secret), setting alg to none, or injecting kid/jku/x5u
headers to supply an attacker-controlled key. Use when testing RS256 JWT auth
for algorithm downgrade, alg:none bypass, or key-confusion signature forgery.
domain: cybersecurity
subdomain: api-security
tags: