web-xss
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as an XSS testing skill, but it equips an AI agent with offensive exploit procedures and explicitly routes stolen browser tokens to an external collaborator service. Install trust is relatively normal and the command-injection finding is a false positive, but the exploit/exfiltration behavior makes the skill high risk.
Confidence: 91%Severity: 76%
Audit Metadata