competition-jwt-claim-confusion

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent for a CTF JWT-analysis purpose and shows no install-chain or credential-exfiltration behavior, but it materially expands an AI agent's offensive security capability by teaching it how to analyze and prove JWT authentication/authorization confusion paths. The main risk is exploit-enablement, not malware or supply-chain abuse.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Mar 31, 2026, 12:17 PM
Package URL
pkg:socket/skills-sh/GALIAIS%2FCTF-Sandbox-Orchestrator%2Fcompetition-jwt-claim-confusion%2F@427c9debb1e5c8ff07d4dbcf8b674be482fc81ec