jwt-token-validator

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is simple JWT-validation assistance, but the actual footprint includes broad npm-backed shell execution and file write capability with no concrete need, package pinning, or verified same-org toolchain. No direct malware or exfiltration is shown, but the permissions are wider than the documented function.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 4, 2026, 02:31 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fjwt-token-validator%2F@c180009b69879aa93d6069d9abf2efe54782b0ea
Security Audit — socket — jwt-token-validator