api-auth-and-jwt-abuse

Fail

Audited by Snyk on Apr 8, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This content is high-risk offensive guidance: it explicitly documents deliberate abuse techniques (JWT alg/kid/jku/x5u attacks and RS256→HS256 confusion), mass-assignment privilege escalation, header spoofing for IP/rate-limit bypass, and batch account/auth abuse — all of which enable token forgery, credential abuse, and authentication boundary circumvention.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 8, 2026, 05:23 AM
Issues
1