xxe-xml-external-entity

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is purpose-aligned as an XXE exploitation playbook, but that purpose is offensive security. It materially equips an AI agent to steal files, hit internal services, and exfiltrate data via OOB channels, so it should be classified as high-risk vulnerable content rather than benign documentation. No strong malware or supply-chain indicators appear in the skill text itself.

Confidence: 95%Severity: 93%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:27 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fxxe-xml-external-entity%2F@9d2397e0defb998ef37d23c63abeeaedf28890f72423b207b2d4c5da6c294242
Security Audit — socket — xxe-xml-external-entity