Cross-Site Scripting and HTML Injection Testing
Fail
Audited by Snyk on Apr 15, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The content explicitly provides payloads and procedures for data exfiltration (cookie/localStorage theft, keylogger), credential harvesting (phishing forms, session hijacking), delivery methods (phishing, URL shorteners, QR codes), and bypass/obfuscation techniques (CSP/WAF bypass, encoded/obfuscated scripts), which together indicate deliberate malicious intent and high-risk abuse potential.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly requires interacting with arbitrary target web application URLs and reading user-generated content (e.g., comment sections, user profiles, search results, and page responses) to detect and exploit XSS, meaning untrusted third-party pages could supply instructions or payloads that materially influence the agent's testing and follow-up actions.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata