jwt-attack
Warn
Audited by Socket on Jul 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive JWT exploitation techniques. There is no obvious credential-harvesting or third-party exfiltration path, yet the exploit capability, disabled TLS verification, and active probing/forgery behavior make it a high-risk security tool rather than a benign developer aid.
Confidence: 93%Severity: 89%
Audit Metadata