xss-html-injection

Solid

Execute comprehensive client-side injection vulnerability assessments on web applications to identify XSS and HTML injection flaws, demonstrate exploitation techniques for session hijacking and credential theft, and validate input sanitization and output encoding mechanisms.

Web & Frontend 43 stars 27 forks Updated yesterday

Install

View on GitHub

Quality Score: 74/100

Stars 20%
55
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
0
Description 5%
100

Skill Content

# Cross-Site Scripting and HTML Injection Testing ## Purpose Execute comprehensive client-side injection vulnerability assessments on web applications to identify XSS and HTML injection flaws, demonstrate exploitation techniques for session hijacking and credential theft, and validate input sanitization and output encoding mechanisms. This skill enables systematic detection and exploitation across stored, reflected, and DOM-based attack vectors. ## Inputs / Prerequisites ### Required Access - Target web application URL with user input fields - Burp Suite or browser developer tools for request analysis - Access to create test accounts for stored XSS testing - Browser with JavaScript console enabled ### Technical Requirements - Understanding of JavaScript execution in browser context - Knowledge of HTML DOM structure and manipulation - Familiarity with HTTP request/response headers - Understanding of cookie attributes and session management ### Legal Prerequisites - Written authorization for security testing - Defined scope including target domains and features - Agreement on handling of any captured session data - Incident response procedures established ## Outputs / Deliverables - XSS/HTMLi vulnerability report with severity classifications - Proof-of-concept payloads demonstrating impact - Session hijacking demonstrations (controlled environment) - Remediation recommendations with CSP configurations ## Core Workflow ### Phase 1: Vulnerability Detection #### Identi...

Details

Author
tody-agent
Repository
tody-agent/codymaster
Created
2 months ago
Last Updated
yesterday
Language
Python
License
None

Related Skills

Web & Frontend Featured

code-to-prd

Reverse-engineer any codebase into a complete Product Requirements Document (PRD). Analyzes routes, components, state management, API integrations, and user interactions to produce business-readable documentation detailed enough for engineers or AI agents to fully reconstruct every page and endpoint. Works with frontend frameworks (React, Vue, Angular, Svelte, Next.js, Nuxt), backend frameworks (NestJS, Django, Express, FastAPI), and fullstack applications. Trigger when users mention: generate PRD, reverse-engineer requirements, code to documentation, extract product specs from code, document page logic, analyze page fields and interactions, create a functional inventory, write requirements from an existing codebase, document API endpoints, or analyze backend routes.

16,173 Updated today
alirezarezvani
Web & Frontend Featured

lifecyclemigrate-from-nextjs

Step-by-step migration from Next.js App Router to TanStack Start: route definition conversion, API mapping, server function conversion from Server Actions, middleware conversion, data fetching pattern changes.

14,498 Updated today
TanStack
Web & Frontend Featured

ckmbanner-design

Design banners for social media, ads, website heroes, creative assets, and print. Multiple art direction options with AI-generated visuals. Actions: design, create, generate banner. Platforms: Facebook, Twitter/X, LinkedIn, YouTube, Instagram, Google Display, website hero, print. Styles: minimalist, gradient, bold typography, photo-based, illustrated, geometric, retro, glassmorphism, 3D, neon, duotone, editorial, collage. Uses ui-ux-pro-max, frontend-design, ai-artist, ai-multimodal skills.

62,072 Updated 1 months ago
nextlevelbuilder