Cross-Site Scripting and HTML Injection Testing

Fail

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill provides numerous functional payloads designed to exfiltrate sensitive browser data to an external server (placeholder attacker.com). Specifically, it includes scripts to capture document.cookie, keystrokes via onkeypress event listeners, and full session metadata (cookies, localStorage, and URL) using fetch or Image object requests.
  • [COMMAND_EXECUTION]: The skill contains examples and instructions for executing arbitrary JavaScript in a victim's browser context. It details the use of dangerous sinks such as eval(), setTimeout(), and Function() constructors to process and execute strings, which is a common pattern for achieving client-side remote code execution.
  • [PROMPT_INJECTION]: The skill's metadata and description explicitly identify malicious use cases like "steal cookies via XSS" and "bypass content security policies" as intended triggers. This framing directs the AI agent to provide actionable exploitation techniques for unauthorized data access.
  • [OBFUSCATION]: The skill documents and provides examples of various obfuscation techniques to bypass security filters (WAFs and CSPs). This includes the use of Base64 encoding (atob), hex encoding, Unicode escapes, and string concatenation (e.g., eval('al'+'ert(1)')) to hide malicious intent from static scanners.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 28, 2026, 05:46 AM
Security Audit — agent-trust-hub — Cross-Site Scripting and HTML Injection Testing