ethosmolt

clawhub:ethosmolt

View source
C
68/100

First Seen

Feb 18, 2026

Last Scanned

Feb 22, 2026

Findings

4

Score

68/100

MEDIUM 4

Findings (4)

MEDIUM
JWT token
L128

Detects JWT tokens

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJzdXBhYmFzZSIsInJlZiI6ImFzeGpzeWpsbmVxb3BjcW9peXNoIiwicm9sZSI6ImFub24iLCJpYXQiOjE3NzA4MzYyMTksImV4cCI6MjA4NjQxMjIxOX0.HctoliV9C6pk3FKvb8jb4wlQQ0aYfoKtSf2...
FIX

Remove hardcoded JWT tokens from the skill definition. Generate tokens dynamically at runtime and set appropriate expiration times.

FP?

Likely FP if the matched text is a documentation example showing JWT structure with clearly fake values, or an expired demo token.

MEDIUM
JWT token
L130

Detects JWT tokens

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJzdXBhYmFzZSIsInJlZiI6ImFzeGpzeWpsbmVxb3BjcW9peXNoIiwicm9sZSI6ImFub24iLCJpYXQiOjE3NzA4MzYyMTksImV4cCI6MjA4NjQxMjIxOX0.HctoliV9C6pk3FKvb8jb4wlQQ0aYfoKtSf2...
FIX

Remove hardcoded JWT tokens from the skill definition. Generate tokens dynamically at runtime and set appropriate expiration times.

FP?

Likely FP if the matched text is a documentation example showing JWT structure with clearly fake values, or an expired demo token.

MEDIUM
JWT token
L131

Detects JWT tokens

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJzdXBhYmFzZSIsInJlZiI6ImFzeGpzeWpsbmVxb3BjcW9peXNoIiwicm9sZSI6ImFub24iLCJpYXQiOjE3NzA4MzYyMTksImV4cCI6MjA4NjQxMjIxOX0.HctoliV9C6pk3FKvb8jb4wlQQ0aYfoKtSf2...
FIX

Remove hardcoded JWT tokens from the skill definition. Generate tokens dynamically at runtime and set appropriate expiration times.

FP?

Likely FP if the matched text is a documentation example showing JWT structure with clearly fake values, or an expired demo token.

MEDIUM
JWT token
L225

Detects JWT tokens

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJzdXBhYmFzZSIsInJlZiI6ImFzeGpzeWpsbmVxb3BjcW9peXNoIiwicm9sZSI6ImFub24iLCJpYXQiOjE3NzA4MzYyMTksImV4cCI6MjA4NjQxMjIxOX0.HctoliV9C6pk3FKvb8jb4wlQQ0aYfoKtSf2...
FIX

Remove hardcoded JWT tokens from the skill definition. Generate tokens dynamically at runtime and set appropriate expiration times.

FP?

Likely FP if the matched text is a documentation example showing JWT structure with clearly fake values, or an expired demo token.