xss-vulnerability-scanner

Warn

Audited by Socket on May 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK vulnerable skill. Its purpose is offensive security scanning, and it grants broad Bash(npm:*) execution plus file write access without concrete package constraints or approval boundaries. No direct credential theft or exfiltration is shown, so this is not confirmed malware, but it is not proportionate to a simple guidance skill.

Confidence: 87%Severity: 79%
Audit Metadata
Analyzed At
May 4, 2026, 02:30 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fxss-vulnerability-scanner%2F@ec91613cbd3d5af6ab204a3aa897bd16217c8764
Security Audit — socket — xss-vulnerability-scanner