offensive-jwt

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is internally consistent with its stated purpose, but that purpose is to perform offensive JWT security testing. It meaningfully expands an AI agent's exploit capability, including auth bypass, brute force, injection, and mobile token extraction, so it should be classified as high security risk but not confirmed malware.

Confidence: 94%Severity: 86%
Audit Metadata
Analyzed At
Sep 15, 2026, 01:32 PM
Package URL
pkg:socket/skills-sh/snailsploit%2Fclaude-red%2Foffensive-jwt%2F@f36c42b8296b8c9f8b1cb6199ce372169b06b071ed049bdf630670aa9eb18dad
Security Audit — socket — offensive-jwt