competition-jwt-claim-confusion
Warn
Audited by Socket on Mar 31, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is internally coherent for a CTF JWT-analysis purpose and shows no install-chain or credential-exfiltration behavior, but it materially expands an AI agent's offensive security capability by teaching it how to analyze and prove JWT authentication/authorization confusion paths. The main risk is exploit-enablement, not malware or supply-chain abuse.
Confidence: 84%Severity: 68%
Audit Metadata