xss-cross-site-scripting

Fail

Audited by Socket on Jul 21, 2026

2 alerts found:

Malwarex2
MalwareHIGH
SKILL.md

MALICIOUS: the skill’s stated and actual purpose is offensive exploitation. It equips an AI agent to execute XSS attacks, evade defenses, exfiltrate victim data, hijack sessions, and escalate to server compromise, which is fundamentally incompatible with a benign developer-assistance skill.

Confidence: 97%Severity: 97%
MalwareHIGH
ADVANCED_XSS_TRICKS.md

The provided fragment is best characterized as malicious exploit/payload material (XSS vectors, service-worker persistence, and XS-Leaks/side-channel inference). There is no evidence of normal dependency functionality or legitimate defensive completeness; instead, it contains actionable instructions/sinks for achieving persistence and client-side compromise. Treat as high-risk malicious/weaponized content if found within a software supply chain artifact.

Confidence: 70%Severity: 90%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:26 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fxss-cross-site-scripting%2F@d8f8c0e1e1e0d4e24e02e9dde79dd21e6794f42a4e3e07e58a5e16b883e18cc3
Security Audit — socket — xss-cross-site-scripting