jwt-oauth-token-attacks

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as an authentication attack playbook, but that stated purpose is itself a high-risk offensive-security capability for an AI agent. Install provenance is mostly acceptable and same-project/official where checked, so the main concern is not malware or credential harvesting by the skill author; it is that the skill equips the agent to run token forgery, brute-force, OAuth account-binding, and token theft attacks against external targets.

Confidence: 92%Severity: 91%
Audit Metadata
Analyzed At
Apr 8, 2026, 05:24 AM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fjwt-oauth-token-attacks%2F@dd07da38417a2b4fa550263fe7f54b2a12f15758