xslt-injection
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent and not a credential stealer or supply-chain lure, but it is a high-risk offensive security skill: it equips the agent to conduct XSLT exploitation, including XXE, SSRF, file write, and RCE testing against real targets. The scanner finding itself is benign documentation context, yet the overall skill should still be treated as dangerous due to exploit-focused capabilities.
Confidence: 94%Severity: 81%
Audit Metadata