xxe-xml-external-entity

Fail

Audited by Socket on Apr 10, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose is explicitly offensive and the actual footprint matches: exploit XML parsers, read sensitive files, pivot to SSRF, and exfiltrate data to attacker-controlled endpoints or Collaborator. No meaningful supply-chain concern appears, but the exploit and exfiltration content make this inappropriate and dangerous for an AI agent skill.

Confidence: 96%Severity: 97%
Audit Metadata
Analyzed At
Apr 10, 2026, 06:20 AM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fxxe-xml-external-entity%2F@4889a975016b7956fd8f9031ebff1418dd9cee8d