payloads-xss-polyglots
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent and contains no installer, credential, or hidden-exfiltration behavior, but it explicitly equips an AI agent with offensive XSS payloads and guidance for blind/stored XSS. This is not malware, yet it is a high-risk exploit-oriented skill.
Confidence: 92%Severity: 76%
Audit Metadata