jwt-oauth-token-attacks

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

HIGH risk offensive-security skill. Its purpose is coherent with its capabilities, but that purpose is to equip an AI agent to perform JWT/OAuth attacks, token theft, and account-takeover techniques. No strong malware indicators or obfuscation are present, yet the exploit-focused guidance makes the skill unsuitable for general deployment.

Confidence: 92%Severity: 90%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:26 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fjwt-oauth-token-attacks%2F@9229ab36852b5fbcb5f9da686b021a9a15eec13a87bc54dc5b1efbde000bd1d1
Security Audit — socket — jwt-oauth-token-attacks