payloads-xss-polyglots

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent and contains no installer, credential, or hidden-exfiltration behavior, but it explicitly equips an AI agent with offensive XSS payloads and guidance for blind/stored XSS. This is not malware, yet it is a high-risk exploit-oriented skill.

Confidence: 92%Severity: 76%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fpayloads-xss-polyglots%2F@e86507b000cf3847fa87e0e0112b2b92e271ea5d6f00edc45a36382a62ab2939
Security Audit — socket — payloads-xss-polyglots