xss-html-injection

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as an XSS testing guide, but its actual footprint is an offensive AI-agent capability that includes credential theft, phishing, session hijacking, and exfiltration demonstrations. There is no malicious installer or hidden execution, yet the exploit-oriented instructions create high misuse risk disproportionate to a normal developer-assistance skill.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Sep 10, 2026, 10:13 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fxss-html-injection%2F@2e1b6efac6e8292ed7497cc6227d2d2613e2262b91225abce97e09df8e503554
Security Audit — socket — xss-html-injection