ai-ml-attacks
This skill should be used when the user asks about "AI security", "ML pipeline attacks", "prompt injection", "model deserialization", "unsafe model loading",…
This skill should be used when the user asks about "XXE", "XML External Entity", "error handling", "exception disclosure", "stack trace exposure", "improper error handling", or needs to find exception-related vulnerabilities during whitebox security review.
$ npx -y skills add allsmog/vuln-scout --skill exception-handling --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/exception-handlingContext preview
The summary Claude sees to decide when to auto-load this skill.
This skill should be used when the user asks about "XXE", "XML External Entity", "error handling", "exception disclosure", "stack trace exposure", "improper error handling", or needs to find exception-related vulnerabilities during whitebox security review.
name: Exception Handling Vulnerabilities description: This skill should be used when the user asks about "XXE", "XML External Entity", "error handling", "exception disclosure", "stack trace exposure", "improper error handling", or needs to find exception-related vulnerabilities during whitebox security review. version: 1.0.0
Provide detection patterns for vulnerabilities related to improper exception and error handling, including XXE (XML External Entity) injection, stack trace disclosure, and authentication bypass via exceptions.
**Category**: Context-dependent
Improper exception handling is not a standalone official OWASP Top 10 bucket. In practice, findings from this skill often map to:
**CWEs**:
Activate this skill when:
---
XXE occurs when XML parsers process external entity references in untrusted XML input, allowing attackers to read files, perform SSRF, or cause DoS.
# Vulnerable XML parsers grep -rniE "DocumentBuilderFactory|SAXParserFactory|XMLInputFactory|TransformerFactory|SchemaFactory|XMLReader" --include="*.java" # Check for disabled external entities (SAFE patterns) grep -rniE "setFeature.*FEATURE_SECURE_PROCESSING|setFeature.*disallow-doctype-decl|setExpandEntityReferences.*false" --include="*.java"
**Vulnerable Pattern**:
// VULNERABLE: Default parser allows XXE DocumentBuilderFactory dbf = DocumentBuilderFactory.newInstance(); DocumentBuilder db = dbf.newDocumentBuilder(); Document doc = db.parse(userInputStream); // XXE possible
**Secure Pattern**:
// SAFE: External entities disabled
DocumentBuilderFactory dbf = DocumentBuilderFactory.newInstance();
dbf.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
dbf.setFeature("http://xml.org/sax/features/external-general-entities", false);
dbf.setFeature("http://xml.org/sax/features/external-parameter-entities", false);# Vulnerable XML parsers grep -rniE "xml\.etree\.ElementTree|xml\.dom\.minidom|xml\.sax|lxml\.etree" --include="*.py" # Check for defusedxml (SAFE) grep -rniE "defusedxml|defused" --include="*.py"
**Vulnerable Pattern**:
# VULNERABLE: Standard library allows XXE import xml.etree.ElementTree as ET tree = ET.parse(user_input) # XXE possible
**Secure Pattern**:
# SAFE: Use defusedxml import defusedxml.ElementTree as ET tree = ET.parse(user_input) # XXE blocked
# Vulnerable XML functions grep -rniE "simplexml_load|DOMDocument|XMLReader|SimpleXMLElement" --include="*.php" # Check for entity loader disabled (SAFE) grep -rniE "libxml_disable_entity_loader|LIBXML_NOENT" --include="*.php"
**Vulnerable Pattern**:
// VULNERABLE: External entities enabled $xml = simplexml_load_string($userInput); // XXE possible
**Secure Pattern**:
// SAFE: Disable external entities (PHP < 8.0) libxml_disable_entity_loader(true); $xml = simplexml_load_string($userInput, 'SimpleXMLElement', LIBXML_NOENT);
# XML parsing grep -rniE "xml\.Unmarshal|xml\.Decoder|xml\.NewDecoder" --include="*.go"
**Note**: Go's `encoding/xml` does not process external entities by default, making it safe from XXE. However, third-party libraries may be vulnerable.
# XML parsing libraries grep -rniE "xml2js|fast-xml-parser|libxmljs|DOMParser|parseFromString" --include="*.ts" --include="*.js"
**Vulnerable Pattern**:
// VULNERABLE: Some libraries allow XXE const parser = new DOMParser(); const doc = parser.parseFromString(userInput, "text/xml");
---
Exposing stack traces or detailed error messages to users reveals internal paths, library versions, and application structure.
# Stack trace printing grep -rniE "printStackTrace|getStackTrace|\.getMessage\(\)" --include="*.java" # Exposed to response grep -rniE "response\.getWriter\(\).*exception|sendError.*getMessage" --include="*.java"
**Vulnerable Pattern**:
// VULNERABLE: Stack trace sent to user
catch (Exception e) {
response.getWriter().println(e.getMessage());
e.printStackTrace(response.getWriter());
}# Traceback exposure grep -rniE "traceback\.print_exc|traceback\.format_exc|sys\.exc_info" --include="*.py" # Debug mode grep -rniE "DEBUG.*=.*True|app\.debug.*=.*True" --include="*.py"
**Vulnerable Pattern**:
# VULNERABLE: Traceback in response
except Exception as e:
return jsonify({"error": traceback.format_exc()}) # Exposes internals# Error display grep -rniE "display_errors|error_reporting|var_dump|print_r" --include="*.php"
**Vulnerable Pattern**:
// VULNERABLE: Errors displayed to users
ini_set('display_errors', 1);
error_reporting(E_ALL);# Stack trace functions grep -rniE "debug\.PrintStack|runtime\.Stack|debug\.Stack" --include="*.go" # Error exposure grep -rniE "http\.Error.*err\.Error\(\)|json\..*err\.Error\(\)" --include="*.go"
**Vulnerable Pattern**:
// VULNERABLE: Internal error exposed
if err != nil {
http.Error(w, err.ErrorAI-powered whitebox penetration testing plugin for Claude Code. 9 languages, 22 skills, 7 autonomous agents. STRIDE threat modeling, OWASP 2025 coverage, polyglot monorepo support.
Repo: allsmog/vuln-scout
This skill should be used when the user asks about "AI security", "ML pipeline attacks", "prompt injection", "model deserialization", "unsafe model loading",…
This skill should be used when the user asks about "business logic", "workflow vulnerability", "trust boundary", "state machine", "authorization bypass",…
This skill should be used when the user asks about "cache poisoning", "web cache deception", "CDN cache", "proxy cache", "nginx cache", "varnish", "cache key…
This skill should be used when the user asks about "cloud security", "AWS security", "GCP security", "Azure security", "Kubernetes security", "IMDS", "instance…
This skill should be used when the user asks about "compliance mapping", "PCI-DSS", "HIPAA", "SOC 2", "NIST CSF", "regulatory requirements", "compliance…
This skill should be used when the user asks about "Code Property Graph", "CPG analysis", "Joern queries", "CPGQL", "data flow verification", "taint tracking…