xss-hunter

Fail

Audited by Socket on Aug 22, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an offensive XSS/pentest skill, but it equips an AI agent with exploit techniques, credential/session theft patterns, exfiltration payloads, phishing, and post-exploitation actions. Install trust is mostly benign, yet the operational capability set makes this a high-risk offensive security skill rather than normal developer guidance.

Confidence: 96%Severity: 93%
MalwareHIGH
references/payloads.md

This fragment is highly suspicious and offensively oriented: it is a weaponizable XSS payload set covering many execution contexts, explicitly includes sensitive cookie/domain access, multiple exfiltration mechanisms to attacker-controlled endpoints, and examples of CSP bypass and authenticated impact. Even though the fragment is not a runnable module by itself, it would materially increase downstream attacker capability if shipped in a supply-chain dependency or delivered as part of software artifacts.

Confidence: 82%Severity: 98%
Audit Metadata
Analyzed At
Aug 22, 2026, 08:12 AM
Package URL
pkg:socket/skills-sh/rifteo%2Fskills%2Fxss-hunter%2F@47e46277465fa1c1125b903086aa22d721dd28438fe466db3964d18595b18a9d
Security Audit — socket — xss-hunter