competition-jwt-claim-confusion

Warn

Audited by Socket on Jun 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent for a CTF JWT-analysis purpose and shows no install-chain or credential-exfiltration behavior, but it materially expands an AI agent's offensive security capability by teaching it how to analyze and prove JWT authentication/authorization confusion paths. The main risk is exploit-enablement, not malware or supply-chain abuse.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Jun 20, 2026, 03:16 AM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Freverse-skill%2Fcompetition-jwt-claim-confusion%2F@ceaf34a7b76d4fc570821f97237a443fe1ed331e2b417ba0877037a583f7b579
Security Audit — socket — competition-jwt-claim-confusion