xxe
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute specialized security tools including
xxeserv,XXEinjector.rb, andoxml_xxe.pyto perform vulnerability testing. - [DATA_EXFILTRATION]: The skill details techniques for exfiltrating sensitive information, such as system files and cloud service credentials, from target applications by exploiting XML parsing vulnerabilities.
Audit Metadata