xxe

Warn

Audited by Socket on Sep 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent, but its purpose is offensive exploitation. Supply-chain risk is low, yet the skill materially enables an AI agent to probe targets, read local files via XXE, trigger SSRF, and exfiltrate data through attacker-controlled callbacks.

Confidence: 94%Severity: 84%
Audit Metadata
Analyzed At
Sep 22, 2026, 05:37 PM
Package URL
pkg:socket/skills-sh/securityfortech%2Fhacking-skills%2Fxxe%2F@713dbb5b66133b3b166c0d948383cd70770e39deb14bd28a7098dc83890352ad
Security Audit — socket — xxe