xss-html-injection

Fail

Audited by Snyk on Jun 2, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This document contains explicit, actionable exploitation payloads and delivery techniques that enable data exfiltration (cookie/session theft, keylogging, localStorage capture), credential harvesting (phishing forms), obfuscated execution (eval/atob/Function) and attacker-hosted callbacks—clear patterns of deliberate malicious intent and abuse potential.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). The skill’s runtime workflow is explicitly about crafting and delivering XSS/HTML injection payloads (including attacker-controlled URLs and payload strings) that would be ingested by the target application and then reflected/processed into the browser DOM/HTML context, which is outsider-authored free text (attacker-supplied payloads) entering the LLM context via any runtime “page content”/response text the agent reads.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 2, 2026, 05:21 AM
Issues
2
Security Audit — snyk — xss-html-injection