offensive-jwt

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is coherent with its stated purpose, but the purpose itself is high risk: it enables an AI agent to conduct offensive JWT exploitation and token extraction against real targets. Install sources are mostly recognizable public security tools rather than obvious malware delivery, and there is no clear third-party credential exfiltration path, but the exploit content, command execution, and sensitive token-access guidance make this a high-risk offensive security skill.

Confidence: 91%Severity: 90%
Audit Metadata
Analyzed At
May 8, 2026, 03:35 AM
Package URL
pkg:socket/skills-sh/SnailSploit%2FClaude-Red%2Foffensive-jwt%2F@1b60e221ff5ed5fd604fc8b3ee9e377156340f80
Security Audit — socket — offensive-jwt