testing-for-json-web-token-vulnerabilities

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s behavior is internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive web-security capabilities. Install sources are mostly coherent, yet the skill facilitates intrusive actions, SSRF/injection testing, secret cracking, and token forgery, and it encourages sending sensitive JWT data to jwt.io.

Confidence: 92%Severity: 88%
Audit Metadata
Analyzed At
Apr 9, 2026, 06:49 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Ftesting-for-json-web-token-vulnerabilities%2F@a12cdd4b1b2446a2ea820ff3c075c5273f2877b9