competition-jwt-claim-confusion

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent with its stated CTF JWT-analysis purpose and shows no direct credential theft or remote execution, but it gives an AI agent offensive JWT exploitation guidance and is distributed through a third-party skills/GitHub trust chain. Main risk is exploit enablement plus moderate supply-chain trust, not confirmed malware.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Jul 30, 2026, 12:52 PM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Fai-fullstack-delivery-workflow%2Fcompetition-jwt-claim-confusion%2F@ceaf34a7b76d4fc570821f97237a443fe1ed331e2b417ba0877037a583f7b579
Security Audit — socket — competition-jwt-claim-confusion