xss-reflected
Warn
Audited by Socket on Sep 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is coherent as an XSS exploitation guide, but it equips an AI agent with offensive security techniques including cookie theft, credential capture, and malware-delivery scenarios. There is no direct installer or credential-harvesting path in the skill itself, so this is not confirmed malware, but it is high-risk due to its exploit-focused purpose and some weak-provenance tool references.
Confidence: 89%Severity: 76%
Audit Metadata