exploit-xss
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: CRITICALOBFUSCATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [OBFUSCATION]: Multiple files utilize Base64 encoding to obfuscate payloads, primarily to demonstrate WAF and filter bypass techniques.
scripts/blind_xss_tester.pycontains a Base64 stringcG9zdChtZXNzYWdlLmNyZWF0ZUVsZW1lbnQoImltZyIpKTsK(decodes topost(message.createElement("img"));) inside aneval(atob())block.assets/svg_xss_payloads.txtincludes a Base64 encoded data URI:data:image/svg+xml;base64,PHN2ZyBvbmxvYWQ9ImFsZXJ0KCdYU1MnKSI+PC9zdmc+(decodes to<svg onload="alert('XSS')">).assets/waf_bypass_payloads.txtcontains<script>eval(atob('YWxlcnQoMSk='))</script>(decodes toalert(1)).- [COMMAND_EXECUTION]: The skill relies on executing external command-line utilities to perform its primary functions.
scripts/xss_full_scan.pyusessubprocess.run()to invoke tools such asdalfox,xsstrike, andxspear.- The
scan_with_dalfoxandscan_with_xsstrikemethods in the same file pass user-controlled target URLs directly into shell commands. - [EXTERNAL_DOWNLOADS]: The skill's documentation (
SKILL.md) and reference guides recommend installing several third-party security tools from GitHub and official package registries. - Recommends installing
XSStrikevia pip,Dalfoxvia Go, andXSpearvia RubyGems. - Includes links to external resources on GitHub (e.g.,
s0md3v/XSStrike,hahwul/dalfox). - [DYNAMIC_EXECUTION]: The skill generates and tests payloads that utilize dynamic JavaScript execution functions to evade detection.
- Numerous payloads in the
assets/directory useeval(),Function(),setTimeout(), andatob()to execute arbitrary code string segments. - [DATA_EXFILTRATION]: The skill provides automated mechanisms for Out-of-band Application Security Testing (OAST) which exfiltrate data from target systems.
scripts/blind_xss_tester.pygenerates payloads that usefetch()or image requests to send data (includingdocument.cookie) to a user-provided callback URL.- Multiple asset files (e.g.,
assets/blind_xss_payloads.txt) contain hardcoded examples of exfiltration payloads. - The skill contains references to known malicious domains such as
evilcdn.com(e.g.,https://evilcdn.com/lib.jsandhttps://evilcdn.com/payload.js) which are flagged by automated scanners, although they are documented as examples for testing purposes.
Recommendations
- Contains 3 malicious URL(s) - DO NOT USE
Audit Metadata