xxe-xml-external-entity
Covers XXE in XML, SVG, OOXML, SOAP, and parser-driven imports. Focuses on external entity resolution that may access files or internal network resources.
Your agent can do more. Find the skill that makes it happen.
Find your next superpower If you are an agent, refer to our llms.txt for full access.Covers XXE in XML, SVG, OOXML, SOAP, and parser-driven imports. Focuses on external entity resolution that may access files or internal network resources.
Query Google Places through goplaces for text searches, place details, resolution, and reviews. Supports scriptable JSON output.
Covers Python, R, SQL, statistical methods, A/B testing, time series, and business intelligence. Supports experiment design, feature engineering, model evaluation, causal inference, and stakeholder communication.
Covers server-side template injection where attacker-controlled content may be evaluated by templating engines. Applies to template expressions, server-side rendering, and preview features.
Provides patterns for S3 buckets, object uploads and downloads, multipart uploads, and object operations. Covers presigned URLs, S3 Transfer Manager, and S3-specific configuration.
Acts as an entry router for file access and upload testing. Covers download endpoints, paths, local file inclusion, previews, archive extraction, and storage or sharing boundaries.
Provides a GraphQL and hidden-parameter testing playbook. Covers introspection, batching, undocumented fields, hidden parameters, schema abuse, and authorization gaps.
Supports designing, reviewing, and refactoring UI component libraries in React and Next.js. Covers responsive layouts, accessibility, theming, dark mode, design tokens, and component composition.
Handles Chinese A-share, index, fund, futures, options, and local DuckDB data through Tonghuashun financial data services. Supports selecting and configuring CLI, MCP, and REST API access for financial data retrieval tasks.
Addresses kernel use-after-free, out-of-bounds access, race conditions, and type confusion. Covers privilege escalation through commit_creds, modprobe_path overwrites, and kernel ROP chains in CTF and real-world scenarios.
Provides unit and integration testing patterns for LangChain4j applications. Creates mock LLM responses, tests retrieval chains, validates RAG workflows, and uses Testcontainers for Java AI service integration tests.
Follows the official quickstart to scaffold a minimal LangGraph agent in TypeScript. Supports quickly building or trying an agent locally.
Skills give your agent reusable instructions for a specific job. Pick one, read what it does, and bring it into your workflow.
A name only tells half the story. Search the full description and instructions to find the right fit.
Read the skill, visit its source, and see exactly what you’re adding to your agent.
Copy the install command from a skill page and run it in your project.
npx skillycli add owner/repo --skill name