xxe-xml-external-entity
Fail
Audited by Socket on Apr 10, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS/HIGH-RISK skill. Its stated purpose is explicitly offensive and the actual footprint matches: exploit XML parsers, read sensitive files, pivot to SSRF, and exfiltrate data to attacker-controlled endpoints or Collaborator. No meaningful supply-chain concern appears, but the exploit and exfiltration content make this inappropriate and dangerous for an AI agent skill.
Confidence: 96%Severity: 97%
Audit Metadata