sast-xss

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is internally consistent and not overtly malicious, but it is a high-risk AI security tool because it enables an agent to perform structured XSS vulnerability discovery and verification against codebases. The main concerns are offensive-security capability, subagent autonomy over untrusted code, and reliance on another skill; there is little evidence of credential theft, exfiltration, or suspicious installs in this snippet.

Confidence: 91%Severity: 78%
Audit Metadata
Analyzed At
Apr 8, 2026, 08:01 AM
Package URL
pkg:socket/skills-sh/utkusen%2Fsast-skills%2Fsast-xss%2F@05944c837b7f03be975faeb056e6668c49c50315