xss-cross-site-scripting

Fail

Audited by Socket on Sep 15, 2026

2 alerts found:

Malwarex2
MalwareHIGH
SKILL.md

MALICIOUS: this skill is an offensive exploit playbook whose actual footprint centers on data theft, persistence, account abuse, and RCE guidance. The scanner's command-injection hit is mostly a documentation false positive, but the explicit exfiltration and attack chaining make the skill fundamentally incompatible with a benign developer-assistance purpose.

Confidence: 97%Severity: 98%
MalwareHIGH
ADVANCED_XSS_TRICKS.md

The provided fragment is best characterized as malicious exploit/payload material (XSS vectors, service-worker persistence, and XS-Leaks/side-channel inference). There is no evidence of normal dependency functionality or legitimate defensive completeness; instead, it contains actionable instructions/sinks for achieving persistence and client-side compromise. Treat as high-risk malicious/weaponized content if found within a software supply chain artifact.

Confidence: 70%Severity: 90%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:15 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fxss-cross-site-scripting%2F@d8f8c0e1e1e0d4e24e02e9dde79dd21e6794f42a4e3e07e58a5e16b883e18cc3
Security Audit — socket — xss-cross-site-scripting