xslt-injection

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPERSISTENCEDYNAMIC_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides comprehensive templates and instructions for achieving Remote Code Execution (RCE) across multiple platforms.
  • Includes PHP-specific payloads using php:function to call assert or write files.
  • Includes Java-specific payloads for Saxon and Xalan engines to execute system commands via java.lang.Runtime.
  • Includes .NET-specific payloads using msxsl:script to execute C# code.
  • [COMMAND_EXECUTION]: Detailed command strings for system reconnaissance and execution are embedded in the skill.
  • Evidence: Payloads include /bin/sh -c id, cmd.exe /c whoami, and ping commands.
  • [DATA_EXFILTRATION]: The skill details methods to access sensitive system files and exfiltrate data to external servers.
  • Evidence: Payloads for reading /etc/passwd and C:/windows/win.ini via XXE entities and the document() function.
  • Evidence: Example provided for SSRF/out-of-band exfiltration targeting http://attacker.example/ssrf.
  • [PERSISTENCE]: The documentation describes how to use file-write primitives to maintain long-term access to a target system.
  • Evidence: Instructions for writing webshells to webroots or malicious scripts to cron paths using exslt:document.
  • [DYNAMIC_EXECUTION]: The skill demonstrates the use of runtime compilation and execution of code within the XSLT processing environment.
  • Evidence: Use of msxsl:script with C# implementation blocks that are compiled and executed at runtime.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:13 PM
Security Audit — agent-trust-hub — xslt-injection