xss-reflected

Warn

Audited by Socket on Sep 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is coherent as an XSS exploitation guide, but it equips an AI agent with offensive security techniques including cookie theft, credential capture, and malware-delivery scenarios. There is no direct installer or credential-harvesting path in the skill itself, so this is not confirmed malware, but it is high-risk due to its exploit-focused purpose and some weak-provenance tool references.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
Sep 22, 2026, 05:37 PM
Package URL
pkg:socket/skills-sh/securityfortech%2Fhacking-skills%2Fxss-reflected%2F@1cbdb95483bc94a7423a240cf973e7cf82aa943d9df30cce02f0e1dca3c11dd0
Security Audit — socket — xss-reflected