jwt-oauth-token-attacks
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK skill. Its instructions are internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive JWT/OAuth attack techniques, including forgery, brute forcing, callback manipulation, and attacker-hosted key injection. I found no confirmed malware, no hidden exfiltration, and no real installer abuse in the supplied content, but the skill materially increases offensive capability and should be treated as high security risk.
Confidence: 93%Severity: 82%
Audit Metadata