Skip to content
Back to skills

Xml

BSecurity

Parse, generate, and transform XML with correct namespace handling and encoding.

  • 17 stars
  • 0 votes
  • 0 copies
  • 4 views
  • Added September 6, 2026
testingnodeexpressapi

Works with

  • api

Security analysis

B75/100
  • criticalAccesses sensitive system or user directories

Pro scans all 2 files and shows the line behind each finding

Scanned September 6, 2026

npx -y skills add clawic/skills --skill xml --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Xml?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Xml
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/clawic-xml/badge)](https://www.skillsdirectory.com/skills/clawic-xml)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: XML
slug: xml
version: 1.0.0
description: Parse, generate, and transform XML with correct namespace handling and encoding.
homepage: https://clawic.com/skills/xml
metadata:
  clawdbot:
    emoji: 📄
    os:
    - linux
    - darwin
    - win32
    displayName: XML
---

## Namespaces

- XPath `/root/child` fails if document has default namespace—use `//*[local-name()='child']` or register prefix
- Default namespace (`xmlns="..."`) applies to elements, not attributes—attributes need explicit prefix
- Namespace prefix is arbitrary—`<foo:element>` and `<bar:element>` are identical if both prefixes map to same URI
- Child elements don't inherit parent's prefixed namespace—each must declare or use prefix explicitly

## Encoding

- `<?xml version="1.0" encoding="UTF-8"?>` must match actual file encoding—mismatch corrupts non-ASCII
- Encoding declaration must be first thing in file—no whitespace or BOM before it (except UTF-8 BOM allowed)
- Default encoding is UTF-8 if declaration omitted—but explicit is safer across parsers

## Escaping & CDATA

- Five entities always escape in text: `&amp;` `&lt;` `&gt;` `&quot;` `&apos;`
- CDATA sections `<![CDATA[...]]>` for blocks with many special chars—but `]]>` inside CDATA breaks it
- Attribute values: use `&quot;` if delimited by `"`, or `&apos;` if delimited by `'`
- Numeric entities `&#60;` and `&#x3C;` work everywhere—useful for edge cases

## Whitespace

- Whitespace between elements is preserved by default—pretty-printing adds nodes that may break processing
- `xml:space="preserve"` attribute signals whitespace significance—but not all parsers respect it
- Normalize-space in XPath: `normalize-space(text())` trims and collapses internal whitespace

## XPath Pitfalls

- `//element` is expensive—traverses entire document; use specific paths when structure is known
- Position is 1-indexed: `[1]` is first, not `[0]`
- `text()` returns direct text children only—use `string()` or `.` for concatenated descendant text
- Boolean in predicates: `[@attr]` tests existence, `[@attr='']` tests empty value—different results

## Structure

- Self-closing `<tag/>` and empty `<tag></tag>` are semantically identical—but some legacy systems choke on self-closing
- Comments cannot contain `--`—will break parser even inside string content
- Processing instructions `<?target data?>` cannot have `?>` in data
- Root element required—document with only comments/PIs and no element is invalid

## Validation

- Well-formed ≠ valid—parser may accept structure but fail against schema
- DTD validates but can't express complex constraints—prefer XSD or RelaxNG for new projects
- XSD namespace `xmlns:xs="http://www.w3.org/2001/XMLSchema"` commonly confused with instance namespace

Files in this skill

  • SKILL.md2.7 KB
  • _meta.json158 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…