acidrain-xss-security-testing
Fail
Audited by Snyk on Aug 23, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). The GitHub clone URL is an untrusted/unknown user repository used to distribute scripts (potentially delivering malicious or unsafe tooling), while the other links are a benign author site and a localhost test endpoint not used for external downloads.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). Contains an explicit cookie-extraction routine and a dedicated exfiltration function that sends harvested data to an external test server — functionality that directly enables credential/data exfiltration and can be abused outside authorized labs.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata