CtrlK
BlogDocsLog inGet started
Tessl Logo

exploit-xxe

XML External Entity (XXE) injection — local file reading via XML parsers, SOAP/WSDL API exploitation, blind out-of-band exfiltration, SVG/DOCX/XLSX upload XXE. Use for any challenge involving XML processing, SOAP endpoints, WSDL services, or XML-based file upload parsing.

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

90%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, highly executable technique reference: nearly every line is a runnable command, detection/validation is front-loaded, and the pitfalls section doubles as error-recovery guidance. Weaknesses are minor — the blind-XXE verification step is a stub comment rather than a concrete check, and the inlined XLSX builder makes the single file longer than an overview-first structure would.

Suggestions

Replace the stub "# 3. Check listener for exfiltrated data" with a concrete verification step, e.g. inspecting the python http.server access log and URL-decoding the %file; value from the request line, so the blind-XXE workflow closes its feedback loop.

Add an explicit response-validation cue after each file-read payload (e.g., grep the response for an expected marker like 'root:' before iterating the credential-file loop) so failed reads are caught early.

Move the XLSX package construction into a scripts/ helper (e.g., build_xxe_xlsx.sh) and keep a one-line invocation in SKILL.md to keep the main file a lean overview.

DimensionReasoningScore

Conciseness

The body is almost entirely executable commands; the only prose is a one-line framing sentence ("Exploits XML parsers that process external entity definitions, enabling local file reading, SSRF, or denial of service") and section comments. It assumes Claude's competence, explains no background concepts, and every block teaches a distinct vector — matching the 5 anchor "lean and efficient" rather than 4's "minor instances of over-explanation".

5 / 5

Actionability

Every section is copy-paste-ready curl/bash: detection probes, the /etc/passwd confirm, a credential-file read loop, SOAP payloads with namespace matching, SVG and XLSX upload construction, a served evil.dtd with a python listener for blind OOB, and URL-encoded variants. Specific examples cover all common XXE cases, matching the 5 anchor; the only imperfection is the bare comment "# 3. Check listener for exfiltrated data", which is incomplete guidance rather than a missing executable step.

5 / 5

Workflow Clarity

Sections sequence logically from Detection ("Read /etc/passwd (confirms XXE)" is an explicit validation checkpoint) through escalating vectors, and "Common Pitfalls" acts as error-recovery guidance ("If entity expansion disabled → try parameter entities"). Not 5: the blind-XXE workflow ends at the stub comment "# 3. Check listener for exfiltrated data" with no verification command, and the file-read loop has no explicit check that reflected entity content actually appeared in the response before iterating.

4 / 5

Progressive Disclosure

No bundle files exist, and the body is cleanly sectioned (Detection, Basic, SOAP, Upload, Blind, Content Types, Pitfalls) with each block needed at exploitation time. Not 5: at ~133 lines with the multi-command XLSX package construction inlined, part of that detail would sit more naturally in a scripts/ helper so SKILL.md stays a lean overview — this is the 4 anchor's "minor organization gaps".

4 / 5

Total

18

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An excellent description: concrete capability list, explicit use-when triggers with concrete phrases, comprehensive natural keywords including the acronym and file formats, and correct third-person voice. The only weakness is the slightly greedy "any challenge involving XML processing" trigger, which creates minor overlap risk with other XML-related skills.

DimensionReasoningScore

Specificity

The description lists four concrete action areas — "local file reading via XML parsers", "SOAP/WSDL API exploitation", "blind out-of-band exfiltration", "SVG/DOCX/XLSX upload XXE" — which comprehensively covers the standard XXE attack classes. This matches the 5 anchor ("multiple specific concrete actions; comprehensive coverage") rather than 4, since no meaningful capability gap is evident.

5 / 5

Completeness

It explicitly answers both questions: the "what" is the four named exploitation capabilities, and the "when" is the explicit clause "Use for any challenge involving XML processing, SOAP endpoints, WSDL services, or XML-based file upload parsing" with concrete trigger phrases. This is a direct match for the 5 anchor's exemplar pattern, and clearly above 4 where the "when" could be more specific.

5 / 5

Trigger Term Quality

Natural trigger terms are comprehensive: "XXE" and "XML External Entity injection" (acronym plus synonym), "SOAP", "WSDL", "XML parsers", "SVG/DOCX/XLSX upload", and "XML processing" — phrasings users would actually say. Only trivial variants (a literal ".xml" extension, "xml api") are absent, which still fits the comprehensive 5 anchor better than 4's "a few natural terms missing".

5 / 5

Distinctiveness Conflict Risk

The niche itself is sharply defined (XXE injection with named vectors and formats), but the trigger "Use for any challenge involving XML processing" is broad enough to fire for adjacent XML skills (e.g., XPath/XSLT injection or XML validation tasks). That is minor overlap risk with closely related skills — the 4 anchor — rather than the minimal-conflict 5 anchor.

4 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.