s3-minio-content-type-xss
Warn
Audited by Socket on Jul 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent, but its purpose is to help an AI agent exploit cloud-storage misconfigurations to achieve stored XSS on target origins. Install trust is mostly normal, yet the capability is offensive by design and includes credential use through an arbitrary S3-compatible endpoint, making the overall skill high risk.
Confidence: 93%Severity: 90%
Audit Metadata