web-xxe

Warn

Audited by Socket on Sep 20, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. It is internally coherent as an XXE exploitation playbook, but its stated purpose is to help an AI agent perform offensive security actions: file theft, SSRF, and out-of-band exfiltration against target systems. No meaningful supply-chain risk is present, yet the operational risk is high because it equips the agent with exploit techniques and attacker-controlled callback flows.

Confidence: 91%Severity: 86%
AnomalyLOW
cheatsheet.md

The fragment documents XXE exploitation techniques and would enable file disclosure, SSRF, and data exfiltration against vulnerable XML-processing applications. It contains no executable malware or package-specific malicious behavior by itself, but it is high-impact offensive security content and describes dangerous payloads. The assessment is limited to the supplied documentation.

Confidence: 99%Severity: 67%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-xxe%2F@424d09a28b23386272fd1166dae0bca00152353469733f9603241333714f8d59
Security Audit — socket — web-xxe