HTML Injection Testing
Warn
Audited by Socket on Feb 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The fragment is dual-use: it provides detailed HTML injection testing techniques and ready-made exploitation templates (phishing, defacement, credential harvesting). While potentially useful for authorized security testing, its breadth and actionable payloads elevate dual-use risk and potential for misuse. In a supply-chain context, distribution of this content should be restricted to vetted, consent-based engagements with clear scoping and safety controls.
Confidence: 65%Severity: 78%
Audit Metadata