Skip to main content

exploit-xxe

XML External Entity (XXE) injection — local file reading via XML parsers, SOAP/WSDL API exploitation, blind out-of-band exfiltration, SVG/DOCX/XLSX upload XXE. Use for any challenge involving XML processing, SOAP endpoints, WSDL services, or XML-based file upload parsing.

Jump to install

Source facts

Repository
PurpleAILAB/Decepticon
Last source activity
June 2, 2026 at 18:57
Detected SKILL.md language
English
Stars
5,128
Forks
990

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.