xxe-xml-external-entity
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill identifies highly sensitive file paths as targets for exfiltration, including SSH private keys (
~/.ssh/id_rsa), AWS credentials (~/.aws/credentials), and application secrets (wp-config.php,web.config). - [DATA_EXFILTRATION]: Instructions are provided for Out-of-Band (OOB) data exfiltration, detailing how to send stolen file contents to attacker-controlled infrastructure (
attacker.com) via HTTP and FTP protocols. - [REMOTE_CODE_EXECUTION]: The playbook covers techniques to escalate from XML parsing to remote code execution using the PHP
expect://wrapper and processor-specific XSLT vulnerabilities (e.g., Java'sRuntime.exec()). - [COMMAND_EXECUTION]: The skill includes shell command snippets for manually crafting malicious Office documents using
zipandunziptools. - [EXTERNAL_DOWNLOADS]: The payloads instruct the agent to fetch malicious DTD (Document Type Definition) files from external, untrusted domains to facilitate blind XXE attacks.
- [INDIRECT_PROMPT_INJECTION]: As a repository of offensive techniques and bypass methods, the skill provides a capability surface where an agent could be influenced to perform unauthorized security testing or data theft if instructions are applied to processed data.
- [DYNAMIC_EXECUTION]: The skill documents the use of dynamic execution functions such as
system()andexec()in the context of XSLT and web service exploits.
Audit Metadata