competition-jwt-claim-confusion
Warn
Audited by Socket on Jul 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is coherent with its stated CTF JWT-analysis purpose and shows no direct credential theft or remote execution, but it gives an AI agent offensive JWT exploitation guidance and is distributed through a third-party skills/GitHub trust chain. Main risk is exploit enablement plus moderate supply-chain trust, not confirmed malware.
Confidence: 85%Severity: 74%
Audit Metadata