xxe-xml-external-entity
Fail
Audited by Snyk on Apr 10, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The content is an explicit, step-by-step offensive playbook that instructs readers how to perform XML External Entity (XXE) attacks — including out-of-band data exfiltration to attacker-controlled servers, theft of credentials/keys (e.g., /proc/self/environ, .ssh, AWS creds), SSRF to internal metadata services, and chains to achieve remote code execution — and therefore clearly enables deliberate malicious activity.
Issues (1)
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata