Cross-Site Scripting and HTML Injection Testing

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMOBFUSCATIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The skill provides multiple examples of techniques used to hide malicious code and bypass security filters.
  • Base64 encoding: The skill demonstrates executing obfuscated JavaScript using eval(atob('YWxlcnQoMSk=')), which decodes to alert(1).
  • Character encoding: Examples include HTML entity encoding (alert(1)), Hex encoding (alert(1)), and Unicode escapes (\u0061lert(1)).
  • Code masking: Demonstrates evading detection through string concatenation ('al'+'ert(1)') and using the Function() constructor or array constructors to execute code without using typical keywords.
  • [DATA_EXFILTRATION]: The skill documents procedures and provides payloads for exfiltrating sensitive information to a third-party domain (attacker.com).
  • Cookie theft: Templates are provided to send document.cookie to external servers via document.location redirection and Image object requests.
  • Keylogging: Payloads demonstrate capturing e.key events and exfiltrating them in real-time to an external URL.
  • Session exfiltration: Includes fetch templates to POST localStorage and cookie data to external endpoints.
  • [DYNAMIC_EXECUTION]: The skill relies on and promotes the use of dangerous sinks for executing dynamically generated or obfuscated JavaScript.
  • It identifies and encourages the use of eval(), Function(), setTimeout(), and innerHTML as primary methods for achieving code execution during assessments.
  • [INDIRECT_PROMPT_INJECTION]: The methodology described involves the agent ingesting and processing potentially malicious untrusted data from web applications.
  • Ingestion points: Search boxes, query parameters, user profile fields, URL fragments, and HTTP headers as identified in Phase 1.
  • Boundary markers: None; the instructions lack delimiters or warnings to treat reflected data as untrusted text rather than instructions.
  • Capability inventory: The skill instructs the agent to use browser developer tools and manual console execution to interact with targets.
  • Sanitization: The skill focuses on exploiting the absence of sanitization rather than implementing it.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — Cross-Site Scripting and HTML Injection Testing