xss-html-injection
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
High-risk offensive security skill. Its capabilities are internally consistent with its stated purpose, but that purpose is to enable an AI agent to perform exploit development, credential theft demonstrations, session hijacking, phishing-style injection, and data exfiltration against web applications. No suspicious installer or third-party credential-forwarding pattern is present, so this is not confirmed malware, but it materially increases offensive abuse potential and should be treated as dangerous.
Confidence: 95%Severity: 93%
Audit Metadata