xxe-xml-external-entity

Fail

Audited by Snyk on Apr 10, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The content is an explicit, step-by-step offensive playbook that instructs readers how to perform XML External Entity (XXE) attacks — including out-of-band data exfiltration to attacker-controlled servers, theft of credentials/keys (e.g., /proc/self/environ, .ssh, AWS creds), SSRF to internal metadata services, and chains to achieve remote code execution — and therefore clearly enables deliberate malicious activity.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 10, 2026, 06:18 AM
Issues
1