xss-cross-site-scripting
Audited by Socket on Jul 21, 2026
2 alerts found:
Malwarex2MALICIOUS: the skill’s stated and actual purpose is offensive exploitation. It equips an AI agent to execute XSS attacks, evade defenses, exfiltrate victim data, hijack sessions, and escalate to server compromise, which is fundamentally incompatible with a benign developer-assistance skill.
The provided fragment is best characterized as malicious exploit/payload material (XSS vectors, service-worker persistence, and XS-Leaks/side-channel inference). There is no evidence of normal dependency functionality or legitimate defensive completeness; instead, it contains actionable instructions/sinks for achieving persistence and client-side compromise. Treat as high-risk malicious/weaponized content if found within a software supply chain artifact.