testing-for-xxe-injection-vulnerabilities

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK offensive skill. Its purpose is coherent with its capabilities, but the capabilities themselves give an AI agent practical exploit, scanning, and exfiltration procedures, including use of known OOB capture services and attacker-controlled sinks. The personal-repo XXEinjector install adds supply-chain risk. Not confirmed malware, but clearly a high-risk exploit skill.

Confidence: 96%Severity: 96%
Audit Metadata
Analyzed At
Apr 9, 2026, 06:49 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Ftesting-for-xxe-injection-vulnerabilities%2F@45d5a54c97f37c2c0afbcb1ac4905904d32c7b66