offensive-xxe
XML External Entity injection testing checklist: classic XXE, blind XXE (out-of-band), XXE via file upload (SVG/docx), XXE in SOAP/REST, error-based XXE, XInclude attacks, and XXE filter bypass. Use for web app XXE testing and bug bounty. Use when performing authorized red-team, pentest, or research work involving xxe.
- Compatibility
- claude-code codex opencode
Pinned to revision 626b01ddea63, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/offensive-xxe/SKILL.md
- skills/offensive-xxe/LICENSE
- skills/offensive-xxe/README.md
- skills/offensive-xxe/agents/openai.yaml
Every link opens the file at its source, pinned to the revision this page describes.