sast-jwt

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a JWT SAST/audit skill, with no obvious credential harvesting or off-platform exfiltration, but it gives an AI agent offensive security review capability and processes untrusted repository content with subagents and file-write access. Main risk is enabling exploit-focused analysis, not malware-like behavior.

Confidence: 83%Severity: 71%
Audit Metadata
Analyzed At
Mar 30, 2026, 06:24 PM
Package URL
pkg:socket/skills-sh/utkusen%2Fsast-skills%2Fsast-jwt%2F@cb1e814059e65832a09b3a954620295962409b81