jwt-token-validator
Warn
Audited by Socket on May 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is simple JWT-validation assistance, but the actual footprint includes broad npm-backed shell execution and file write capability with no concrete need, package pinning, or verified same-org toolchain. No direct malware or exfiltration is shown, but the permissions are wider than the documented function.
Confidence: 84%Severity: 56%
Audit Metadata