acidrain-xss-security-testing

Fail

Audited by Snyk on Aug 23, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). The GitHub clone URL is an untrusted/unknown user repository used to distribute scripts (potentially delivering malicious or unsafe tooling), while the other links are a benign author site and a localhost test endpoint not used for external downloads.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). Contains an explicit cookie-extraction routine and a dedicated exfiltration function that sends harvested data to an external test server — functionality that directly enables credential/data exfiltration and can be abused outside authorized labs.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 23, 2026, 03:32 PM
Issues
2
Security Audit — snyk — acidrain-xss-security-testing