jwt-oauth-token-attacks

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its instructions are internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive JWT/OAuth attack techniques, including forgery, brute forcing, callback manipulation, and attacker-hosted key injection. I found no confirmed malware, no hidden exfiltration, and no real installer abuse in the supplied content, but the skill materially increases offensive capability and should be treated as high security risk.

Confidence: 93%Severity: 82%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fjwt-oauth-token-attacks%2F@9229ab36852b5fbcb5f9da686b021a9a15eec13a87bc54dc5b1efbde000bd1d1
Security Audit — socket — jwt-oauth-token-attacks