xss-html-injection
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as an XSS testing guide, but its actual footprint is an offensive AI-agent capability that includes credential theft, phishing, session hijacking, and exfiltration demonstrations. There is no malicious installer or hidden execution, yet the exploit-oriented instructions create high misuse risk disproportionate to a normal developer-assistance skill.
Confidence: 89%Severity: 82%
Audit Metadata