skills/byamb4/find-cve-agent/xxe/Gen Agent Trust Hub

xxe

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides various shell commands using grep and semgrep to search the local filesystem for XML parser definitions and configuration settings. These are intended for security researchers to identify potential vulnerability sinks.
  • [PROMPT_INJECTION]: The skill contains example XML payloads for file reading, SSRF, and blind XXE (e.g., referencing /etc/passwd or attacker.com). These are explicitly documented as proof-of-concept templates for vulnerability verification and are not executed against the user's environment.
  • [EXTERNAL_DOWNLOADS]: A Python PoC template is provided in references/poc-skeleton.md which utilizes the requests library to demonstrate payload delivery. This is a static template for user reference.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 05:07 PM
Security Audit — agent-trust-hub — xxe