xslt-injection
Warn
Audited by Socket on Jul 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK offensive security skill. Its behavior is coherent with its stated XSLT-injection purpose, but it explicitly teaches SSRF, file read/write, and RCE techniques for AI-agent use, including cross-loading related exploit skills. No evidence of hidden malware, credential theft, or suspicious installer provenance was found.
Confidence: 91%Severity: 84%
Audit Metadata