testing-for-xml-injection-vulnerabilities

Fail

Audited by Snyk on Mar 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). This is a dual-use penetration-testing guide but contains explicit, intentional exploit payloads and workflows enabling data exfiltration (XXE with external DTD/OOB callbacks, DNS/HTTP exfiltration), credential theft (SSRF to cloud metadata endpoints), and denial-of-service (Billion Laughs/entity expansion), any of which can be directly abused to compromise systems if used without authorization.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 15, 2026, 01:52 PM
Issues
1