testing-for-json-web-token-vulnerabilities

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose is coherent, but that purpose is offensive exploitation of JWT-based authentication systems, which is inappropriate to grant an AI agent without strict oversight. Risk is elevated further by the unpinned personal-repo install for jwt_tool and by sending JWT data through third-party tooling like jwt.io. This is not confirmed malware, but it is a high-risk offensive security skill.

Confidence: 92%Severity: 88%
Audit Metadata
Analyzed At
Mar 15, 2026, 01:54 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Ftesting-for-json-web-token-vulnerabilities%2F@41c69776ca62ca66fd304faa9bd67b1e4309f074