jwt-attack

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive JWT exploitation techniques. There is no obvious credential-harvesting or third-party exfiltration path, yet the exploit capability, disabled TLS verification, and active probing/forgery behavior make it a high-risk security tool rather than a benign developer aid.

Confidence: 93%Severity: 89%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fjwt-attack%2F@98cc2609499a82fc00580a5f29a3de0ae7e53874e86a1520434c5f202888712e
Security Audit — socket — jwt-attack