xsstrike

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

BENIGN in purpose alignment but HIGH RISK in use: the skill is coherently scoped to XSStrike and its data flows match an XSS scanner, with no clear credential theft or hidden exfiltration. However, it gives an AI agent offensive security testing capability and uses a mutable source-based install path with unpinned dependencies, so it should be treated as a legitimate but security-sensitive exploit-tool skill.

Confidence: 89%Severity: 78%
AnomalyLOW
references/xss-context-bypass.md

The fragment is an offensive security reference containing executable XSS and blind-XSS test payloads. It can facilitate exploitation and external callback loading when used against vulnerable applications, but it does not contain package malware or autonomous malicious behavior. Use should be limited to authorized testing environments.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:59 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fxsstrike%2F@ee723c18babc04cdabab9752b345ab26dc083598fecda730fb4c5d798a211c9a
Security Audit — socket — xsstrike