xslt-injection

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is not malware and shows no suspicious installer or credential-harvesting behavior, but it is a high-risk offensive security skill. Its actual footprint matches its stated purpose: teaching AI agents how to probe and exploit XSLT injection up to file access and RCE on target systems.

Confidence: 94%Severity: 82%
Audit Metadata
Analyzed At
Apr 9, 2026, 04:29 AM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fxslt-injection%2F@5af015be3230e509cb8589021ec28d300bf9a777