xslt-injection

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent and not a credential stealer or supply-chain lure, but it is a high-risk offensive security skill: it equips the agent to conduct XSLT exploitation, including XXE, SSRF, file write, and RCE testing against real targets. The scanner finding itself is benign documentation context, yet the overall skill should still be treated as dangerous due to exploit-focused capabilities.

Confidence: 94%Severity: 81%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fxslt-injection%2F@7984ebf4f4e2bf07c82f872ff9ecd12f2e4037582b2561910d2eb102bf6b4179
Security Audit — socket — xslt-injection