Test JSON Web Tokens against common vulnerability patterns. All attacks run client-side — no data is sent to any server.