xss-detection

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent as an XSS pentesting skill, but that stated purpose is itself high risk for an AI agent because it enables offensive security actions and automated exploitation workflows. Supply-chain risk is moderate: Dalfox is official same-org, while the XSStrike install instruction is inconsistent with upstream docs and raises trust concerns.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Mar 13, 2026, 09:21 PM
Package URL
pkg:socket/skills-sh/TerminalSkills%2Fskills%2Fxss-detection%2F@b7f4646ecf7855cf26fd52c30444e8fe7681b978