jwt-key-id-injector: check against hypothetical JWT vulnerability

jwt-pwn