What problem does it solve?
Existing identity and compliance frameworks (NIST 800-53, ISO 27001, NIS2) were designed for traditional network-centric authentication and lack controls for verifiable credential and digital wallet trust verification. This leaves verifiers vulnerable to accepting forged, revoked, or replayed credentials from unanchored issuers, unread status lists, or unbound presentations, creating unaddressed security gaps for EUDI wallet, mobile driving licence, and other VC use cases.
Core Features & Use Cases
- Threat & Compliance Gap Mapping: Maps verifier trust failures to MITRE ATT&CK TTPs (T1556, T1550, T1606) and CWE weaknesses, and flags insufficient controls in NIST, ISO, NIS2, and UK CAF frameworks.
- Step-by-Step Verifier Audit Procedure: Provides a repeatable 6-step process to audit every credential acceptance path for missing trust checks, including issuer anchor pinning, revocation enforcement, nonce/audience binding, and algorithm allowlisting.
- Use Case: For teams rolling out EUDI wallet or ISO 18013-5 mobile driving licence acceptance, this skill identifies exploitable gaps that let attackers bypass credential verification to gain unauthorized access to age-gated services, payments, or identity systems.
Quick Start
Use the vc-wallet-trust skill to audit your digital wallet verifier's trust controls for SD-JWT-VC, OID4VP, and mdoc credential acceptance paths to identify forged, revoked, or replayed credential risks.