xxe-xml-external-entity

Warn

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXFILTRATION]: Documents methods for accessing sensitive system files and transmitting them to external infrastructure.\n
  • Payloads target high-value files including /etc/shadow, /etc/passwd, ~/.ssh/id_rsa, and ~/.aws/credentials in SKILL.md (Section 4).\n
  • Instructions detail exfiltrating this data to attacker.com via HTTP, FTP, and DNS channels using Out-of-Band (OOB) DTDs in SKILL.md (Section 3 and 14).\n- [REMOTE_CODE_EXECUTION]: Provides payloads to execute arbitrary system commands through the XML parser.\n
  • Section 4 of SCENARIOS.md details the use of expect://id for direct command execution.\n
  • Section 19 of SKILL.md covers XSLT injection targeting Java (java.lang.Runtime) and PHP (system) environments.\n- [PROMPT_INJECTION]: Uses an AI LOAD INSTRUCTION block to influence the agent's persona and behavior.\n
  • The instruction block in SKILL.md prompts the model to adopt Expert XXE techniques.\n
  • Ingestion points: The agent context is populated by the instructional content in SKILL.md and SCENARIOS.md.\n
  • Boundary markers: No delimiters or safety warnings are used to separate the instructional content from the malicious payload examples.\n
  • Capability inventory: The skill enables file-system access, network requests, and shell execution via the described XXE vectors.\n
  • Sanitization: No escaping or validation logic is present for the included payloads.\n- [COMMAND_EXECUTION]: Includes shell commands for the weaponization of legitimate files.\n
  • Instructions in SKILL.md (Section 6) and SCENARIOS.md (Section 2) involve using unzip and zip to inject malicious DTDs into Office documents.\n- [EXTERNAL_DOWNLOADS]: References external URLs for hosting malicious resources.\n
  • Payloads reference http://attacker.com/evil.dtd and other variations for OOB attacks and data exfiltration.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 21, 2026, 01:24 PM
Security Audit — agent-trust-hub — xxe-xml-external-entity