xxe-injection-methodology
Fail
Audited by Snyk on Apr 22, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This skill content is an explicit exploitation guide for XXE that provides step-by-step payloads (including blind external DTD exfiltration, php://filter base64 tricks, SOAP/SVG/DOCX exploitation) and instructions to use attacker-controlled servers (http.server, nc) for OOB callbacks, enabling unauthorized data exfiltration and server-side abuse.
Issues (1)
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata