web-auth-jwt
Audited by Socket on Sep 20, 2026
2 alerts found:
SecurityAnomalyThis skill is purpose-aligned but high-risk: it is explicitly an offensive JWT exploitation playbook for AI agents. It shows no strong signs of malware or hidden exfiltration, yet it materially increases an agent's capability to attack external systems, so it should be treated as a dangerous security skill rather than a benign developer helper.
This is offensive JWT penetration-testing guidance, not executable package code. It documents potentially dangerous exploitation techniques, including authentication bypass, key injection, SSRF, path traversal, and SQL injection testing. It contains no direct malware behavior, credential theft, persistence, or automatic network activity in the supplied fragment. Use is appropriate only against authorized test systems.