Cross-Site Scripting and HTML Injection Testing

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the static findings themselves are mostly benign documentation artifacts, but the skill is fundamentally an offensive security/exploit guide for an AI agent. Its actual footprint is to help perform XSS attacks, steal cookies, capture sessions, phish credentials, and deliver malicious links; that is high-risk and not a normal benign developer workflow skill.

Confidence: 91%Severity: 88%
Audit Metadata
Analyzed At
Sep 14, 2026, 07:20 AM
Package URL
pkg:socket/skills-sh/googyosoo%2Fantigravity-skills%2Fcross-site-scripting-and-html-injection-testing%2F@f03fea5b4eb16bb5b43c73b5006b41ab68d47dd9
Security Audit — socket — Cross-Site Scripting and HTML Injection Testing