web-auth-jwt

Warn

Audited by Socket on Sep 20, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

This skill is purpose-aligned but high-risk: it is explicitly an offensive JWT exploitation playbook for AI agents. It shows no strong signs of malware or hidden exfiltration, yet it materially increases an agent's capability to attack external systems, so it should be treated as a dangerous security skill rather than a benign developer helper.

Confidence: 91%Severity: 79%
AnomalyLOW
cheatsheet.md

This is offensive JWT penetration-testing guidance, not executable package code. It documents potentially dangerous exploitation techniques, including authentication bypass, key injection, SSRF, path traversal, and SQL injection testing. It contains no direct malware behavior, credential theft, persistence, or automatic network activity in the supplied fragment. Use is appropriate only against authorized test systems.

Confidence: 99%Severity: 55%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-auth-jwt%2F@a1a3fe8c2a7bf8cc9ffd901b619093879543d6df564836089b3230afca6f807c
Security Audit — socket — web-auth-jwt