web-xss

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as an XSS testing skill, but it equips an AI agent with offensive exploit procedures and explicitly routes stolen browser tokens to an external collaborator service. Install trust is relatively normal and the command-injection finding is a false positive, but the exploit/exfiltration behavior makes the skill high risk.

Confidence: 91%Severity: 76%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-xss%2F@703fe316725bee6740a7ca2714770901b261ab812be326316aaedd7daaff07d8
Security Audit — socket — web-xss