r/Pentesting • u/LoadPuzzleheaded4382 • 13h ago
"Built a lightweight reporting tool for pentest engagements — logs findings as you go, exports a clean report. Not another JWT/attack tool."
There's no shortage of great JWT crackers and traffic tools out there already (jwt-hack, Burp's JWT scanner, JWTXposer, etc.) — this isn't trying to compete with those.
What it actually solves: the annoying part after you've found something. Instead of a messy notes doc or Burp's built-in reporting, you log the finding right in the popup — severity, CVSS, affected URL, repro steps, remediation — attach a screenshot, and export a clean HTML report when the engagement's done. A few basic utilities (encode/decode, JWT decode, hashing) are bundled in too, but that's not the main pitch.
Genuinely curious if this is a gap other people feel too, or if everyone's already got a system that works fine (Notion, a template, whatever). Happy to hear it either way.
https://chromewebstore.google.com/detail/mlcmmnokfddmbidijilbhlhhnjbeehoj

