xxe
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides various shell commands using
grepandsemgrepto search the local filesystem for XML parser definitions and configuration settings. These are intended for security researchers to identify potential vulnerability sinks. - [PROMPT_INJECTION]: The skill contains example XML payloads for file reading, SSRF, and blind XXE (e.g., referencing
/etc/passwdorattacker.com). These are explicitly documented as proof-of-concept templates for vulnerability verification and are not executed against the user's environment. - [EXTERNAL_DOWNLOADS]: A Python PoC template is provided in
references/poc-skeleton.mdwhich utilizes therequestslibrary to demonstrate payload delivery. This is a static template for user reference.
Audit Metadata