HTML Injection Testing
Warn
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DATA_EXFILTRATION]: Provides functional payloads designed to exfiltrate session cookies by appending
document.cookieto a request targeting an external domain (attacker.com). - [DATA_EXFILTRATION]: Includes complete HTML/CSS templates for phishing forms that capture user credentials and transmit them to a remote server (
attacker.com/capture). - [COMMAND_EXECUTION]: Contains a Python automation script using the
requestslibrary to perform automated fuzzing and injection testing against target web applications. - [COMMAND_EXECUTION]: Provides specific
curlcommand patterns for testing reflected HTML injection in both GET and POST requests. - [EXTERNAL_DOWNLOADS]: Payloads in the skill instructions reference external, non-whitelisted domains for loading remote images, creating iframes, and performing meta-refresh redirects.
Audit Metadata