xxe-xml-external-entity

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill identifies highly sensitive file paths as targets for exfiltration, including SSH private keys (~/.ssh/id_rsa), AWS credentials (~/.aws/credentials), and application secrets (wp-config.php, web.config).
  • [DATA_EXFILTRATION]: Instructions are provided for Out-of-Band (OOB) data exfiltration, detailing how to send stolen file contents to attacker-controlled infrastructure (attacker.com) via HTTP and FTP protocols.
  • [REMOTE_CODE_EXECUTION]: The playbook covers techniques to escalate from XML parsing to remote code execution using the PHP expect:// wrapper and processor-specific XSLT vulnerabilities (e.g., Java's Runtime.exec()).
  • [COMMAND_EXECUTION]: The skill includes shell command snippets for manually crafting malicious Office documents using zip and unzip tools.
  • [EXTERNAL_DOWNLOADS]: The payloads instruct the agent to fetch malicious DTD (Document Type Definition) files from external, untrusted domains to facilitate blind XXE attacks.
  • [INDIRECT_PROMPT_INJECTION]: As a repository of offensive techniques and bypass methods, the skill provides a capability surface where an agent could be influenced to perform unauthorized security testing or data theft if instructions are applied to processed data.
  • [DYNAMIC_EXECUTION]: The skill documents the use of dynamic execution functions such as system() and exec() in the context of XSLT and web service exploits.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:13 PM
Security Audit — agent-trust-hub — xxe-xml-external-entity