testing-for-xml-injection-vulnerabilities
Fail
Audited by Snyk on Mar 15, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). This is a dual-use penetration-testing guide but contains explicit, intentional exploit payloads and workflows enabling data exfiltration (XXE with external DTD/OOB callbacks, DNS/HTTP exfiltration), credential theft (SSRF to cloud metadata endpoints), and denial-of-service (Billion Laughs/entity expansion), any of which can be directly abused to compromise systems if used without authorization.
Issues (1)
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata