xxe-xml-external-entity
Warn
Audited by Socket on Jul 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This skill is purpose-aligned as an XXE exploitation playbook, but that purpose is offensive security. It materially equips an AI agent to steal files, hit internal services, and exfiltrate data via OOB channels, so it should be classified as high-risk vulnerable content rather than benign documentation. No strong malware or supply-chain indicators appear in the skill text itself.
Confidence: 95%Severity: 93%
Audit Metadata