performing-jwt-none-algorithm-attack

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent, but its stated purpose is to perform an authentication-bypass attack and it gives an AI agent offensive security automation against external targets. Install trust is mostly normal; the primary risk is the exploit capability and autonomous network use, not malware or hidden exfiltration.

Confidence: 92%Severity: 83%
Audit Metadata
Analyzed At
Apr 9, 2026, 06:50 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fperforming-jwt-none-algorithm-attack%2F@97ca9f915042db4d8b89f48f8a62c2f4d618af6d