xss-hunter
Audited by Socket on Aug 22, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS: the skill is internally consistent as an offensive XSS/pentest skill, but it equips an AI agent with exploit techniques, credential/session theft patterns, exfiltration payloads, phishing, and post-exploitation actions. Install trust is mostly benign, yet the operational capability set makes this a high-risk offensive security skill rather than normal developer guidance.
This fragment is highly suspicious and offensively oriented: it is a weaponizable XSS payload set covering many execution contexts, explicitly includes sensitive cookie/domain access, multiple exfiltration mechanisms to attacker-controlled endpoints, and examples of CSP bypass and authenticated impact. Even though the fragment is not a runnable module by itself, it would materially increase downstream attacker capability if shipped in a supply-chain dependency or delivered as part of software artifacts.