xss-html-injection
Warn
Audited by Socket on Jun 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK offensive skill. Its capabilities align with its stated purpose, but that purpose is to enable exploitation: it includes credential theft, session hijacking, phishing, CSP bypass, and exfiltration payloads to attacker-controlled endpoints. There is little supply-chain risk, but the operational risk is high because the skill gives an AI agent concrete offensive techniques with real-world harm potential.
Confidence: 97%Severity: 93%
Audit Metadata