xxe

Fail

Audited by Socket on May 12, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent as an XXE detection guide and shows no credential theft, hidden installs, or third-party data routing, but it is a security/exploit-oriented agent skill that teaches vulnerability discovery and validation. Risk comes mainly from enabling offensive security workflows, not from malicious data flow or supply-chain behavior in the skill itself.

Confidence: 91%Severity: 72%
MalwareHIGH
references/poc-skeleton.md

This code fragment is explicit, actionable XXE exploitation material. It includes local file disclosure, SSRF to the cloud instance metadata service, and blind/out-of-band exfiltration using attacker-controlled external DTDs, plus a Python sender that delivers the payload to a target XML parsing endpoint. If present in a software supply chain dependency, it should be treated as extremely malicious/high-risk and not used or executed outside tightly controlled research environments.

Confidence: 90%Severity: 100%
Audit Metadata
Analyzed At
May 12, 2026, 05:10 PM
Package URL
pkg:socket/skills-sh/ByamB4%2Ffind-cve-agent%2Fxxe%2F@d455a7e6dad2cba983f5ee3aa8859ff6945e16a5
Security Audit — socket — xxe