s3-minio-content-type-xss

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent, but its purpose is to help an AI agent exploit cloud-storage misconfigurations to achieve stored XSS on target origins. Install trust is mostly normal, yet the capability is offensive by design and includes credential use through an arbitrary S3-compatible endpoint, making the overall skill high risk.

Confidence: 93%Severity: 90%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fs3-minio-content-type-xss%2F@68ad6698ce450b7006e376816156b7d445024c35f1fd576566868fe13ca2928b
Security Audit — socket — s3-minio-content-type-xss