jwt-tool

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with its stated purpose, but that purpose is an offensive JWT exploitation toolkit for an AI agent. The main concern is not deceptive install behavior; it is that the skill enables automated security testing and active exploitation against target services, including forged-token delivery to remote URLs. Treat as a high-risk offensive-security skill rather than confirmed malware.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fjwt-tool%2F@4964c578d1c2be6fcf5d749ee98f2337ba58ed969bcb52dfc3929f60e8699150
Security Audit — socket — jwt-tool