exploit-xss

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: CRITICALOBFUSCATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [OBFUSCATION]: Multiple files utilize Base64 encoding to obfuscate payloads, primarily to demonstrate WAF and filter bypass techniques.
  • scripts/blind_xss_tester.py contains a Base64 string cG9zdChtZXNzYWdlLmNyZWF0ZUVsZW1lbnQoImltZyIpKTsK (decodes to post(message.createElement("img"));) inside an eval(atob()) block.
  • assets/svg_xss_payloads.txt includes a Base64 encoded data URI: data:image/svg+xml;base64,PHN2ZyBvbmxvYWQ9ImFsZXJ0KCdYU1MnKSI+PC9zdmc+ (decodes to <svg onload="alert('XSS')">).
  • assets/waf_bypass_payloads.txt contains <script>eval(atob('YWxlcnQoMSk='))</script> (decodes to alert(1)).
  • [COMMAND_EXECUTION]: The skill relies on executing external command-line utilities to perform its primary functions.
  • scripts/xss_full_scan.py uses subprocess.run() to invoke tools such as dalfox, xsstrike, and xspear.
  • The scan_with_dalfox and scan_with_xsstrike methods in the same file pass user-controlled target URLs directly into shell commands.
  • [EXTERNAL_DOWNLOADS]: The skill's documentation (SKILL.md) and reference guides recommend installing several third-party security tools from GitHub and official package registries.
  • Recommends installing XSStrike via pip, Dalfox via Go, and XSpear via RubyGems.
  • Includes links to external resources on GitHub (e.g., s0md3v/XSStrike, hahwul/dalfox).
  • [DYNAMIC_EXECUTION]: The skill generates and tests payloads that utilize dynamic JavaScript execution functions to evade detection.
  • Numerous payloads in the assets/ directory use eval(), Function(), setTimeout(), and atob() to execute arbitrary code string segments.
  • [DATA_EXFILTRATION]: The skill provides automated mechanisms for Out-of-band Application Security Testing (OAST) which exfiltrate data from target systems.
  • scripts/blind_xss_tester.py generates payloads that use fetch() or image requests to send data (including document.cookie) to a user-provided callback URL.
  • Multiple asset files (e.g., assets/blind_xss_payloads.txt) contain hardcoded examples of exfiltration payloads.
  • The skill contains references to known malicious domains such as evilcdn.com (e.g., https://evilcdn.com/lib.js and https://evilcdn.com/payload.js) which are flagged by automated scanners, although they are documented as examples for testing purposes.
Recommendations
  • Contains 3 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 16, 2026, 03:47 PM
Security Audit — agent-trust-hub — exploit-xss