xss-cross-site-scripting
Audited by Socket on Sep 15, 2026
2 alerts found:
Malwarex2MALICIOUS: this skill is an offensive exploit playbook whose actual footprint centers on data theft, persistence, account abuse, and RCE guidance. The scanner's command-injection hit is mostly a documentation false positive, but the explicit exfiltration and attack chaining make the skill fundamentally incompatible with a benign developer-assistance purpose.
The provided fragment is best characterized as malicious exploit/payload material (XSS vectors, service-worker persistence, and XS-Leaks/side-channel inference). There is no evidence of normal dependency functionality or legitimate defensive completeness; instead, it contains actionable instructions/sinks for achieving persistence and client-side compromise. Treat as high-risk malicious/weaponized content if found within a software supply chain artifact.