testing-for-json-web-token-vulnerabilities
Warn
Audited by Socket on Apr 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s behavior is internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive web-security capabilities. Install sources are mostly coherent, yet the skill facilitates intrusive actions, SSRF/injection testing, secret cracking, and token forgery, and it encourages sending sensitive JWT data to jwt.io.
Confidence: 92%Severity: 88%
Audit Metadata