Cross-Site Scripting and HTML Injection Testing

Fail

Audited by Snyk on Apr 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The content explicitly provides payloads and procedures for data exfiltration (cookie/localStorage theft, keylogger), credential harvesting (phishing forms, session hijacking), delivery methods (phishing, URL shorteners, QR codes), and bypass/obfuscation techniques (CSP/WAF bypass, encoded/obfuscated scripts), which together indicate deliberate malicious intent and high-risk abuse potential.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly requires interacting with arbitrary target web application URLs and reading user-generated content (e.g., comment sections, user profiles, search results, and page responses) to detect and exploit XSS, meaning untrusted third-party pages could supply instructions or payloads that materially influence the agent's testing and follow-up actions.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 15, 2026, 06:10 PM
Issues
2
Security Audit — snyk — Cross-Site Scripting and HTML Injection Testing