Cross-Site Scripting and HTML Injection Testing

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The file is a comprehensive and accurate XSS/HTML injection testing guide suitable for authorized security assessments. However, it contains multiple explicit, ready-to-use exfiltration payloads and detailed delivery/bypass techniques (including hard-coded attacker endpoints and phishing form examples) that materially increase the chance of misuse. Recommend sanitizing public versions by removing or redacting explicit attacker endpoints, replacing exfiltration examples with instructions to use local/test collectors, and emphasizing safe-sink best practices. Use only in authorized, scoped engagements and ensure testers use internal/non-production sinks for proofs-of-concept.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 07:58 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fcross-site-scripting-and-html-injection-testing%2F@f03fea5b4eb16bb5b43c73b5006b41ab68d47dd9