testing-jwt-token-security

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as a JWT penetration-testing guide, but it gives an AI agent high-risk offensive security capabilities, installs third-party tooling with weak pinning, and performs active exploitation against targets. This is not confirmed malware, but it is a high-risk skill that should be tightly controlled and used only with explicit authorization and human oversight.

Confidence: 92%Severity: 86%
Audit Metadata
Analyzed At
Mar 15, 2026, 12:27 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Ftesting-jwt-token-security%2F@767c1ead70fde735ae2f35245a9a5c3d961c00d4