sast-jwt

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

BENIGN for internal consistency: the skill’s capabilities match its stated purpose of JWT-focused SAST and local reporting, with no suspicious installs, credential harvesting, or off-platform data routing. The main concern is that it equips an AI agent with offensive security testing guidance against JWT implementations, making it a higher-risk security skill rather than a malicious one.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Sep 20, 2026, 03:35 AM
Package URL
pkg:socket/skills-sh/utkusen%2Fsast-skills%2Fsast-jwt%2F@76465a2c2461442e73199b2fceae353e5783e2308ea9f6bbcdadbf0798e7c088
Security Audit — socket — sast-jwt