auth-bypass
Audited by Socket on May 12, 2026
2 alerts found:
Securityx2This fragment is high-risk offensive PoC material for bypassing API authentication/authorization (missing/incorrect endpoint protection, JWT algorithm confusion including alg=none crafting, and IDOR testing). While it does not itself demonstrate malware behavior such as persistence or exfiltration, distributing such code in a software supply chain would materially increase the capability for unauthorized access attempts against vulnerable services. Treat as malicious-use guidance rather than benign library code.
SUSPICIOUS. The skill is internally coherent and does not show credential theft, exfiltration, or supply-chain abuse, but it equips an AI agent with offensive security auditing capability focused on authentication bypass discovery. That makes it high risk as a security/exploit skill even though the implementation footprint is otherwise minimal and local-only.