xsstrike
Audited by Socket on Sep 15, 2026
2 alerts found:
SecurityAnomalyBENIGN in purpose alignment but HIGH RISK in use: the skill is coherently scoped to XSStrike and its data flows match an XSS scanner, with no clear credential theft or hidden exfiltration. However, it gives an AI agent offensive security testing capability and uses a mutable source-based install path with unpinned dependencies, so it should be treated as a legitimate but security-sensitive exploit-tool skill.
The fragment is an offensive security reference containing executable XSS and blind-XSS test payloads. It can facilitate exploitation and external callback loading when used against vulnerable applications, but it does not contain package malware or autonomous malicious behavior. Use should be limited to authorized testing environments.