HTML Injection Testing

Warn

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXFILTRATION]: Provides functional payloads designed to exfiltrate session cookies by appending document.cookie to a request targeting an external domain (attacker.com).
  • [DATA_EXFILTRATION]: Includes complete HTML/CSS templates for phishing forms that capture user credentials and transmit them to a remote server (attacker.com/capture).
  • [COMMAND_EXECUTION]: Contains a Python automation script using the requests library to perform automated fuzzing and injection testing against target web applications.
  • [COMMAND_EXECUTION]: Provides specific curl command patterns for testing reflected HTML injection in both GET and POST requests.
  • [EXTERNAL_DOWNLOADS]: Payloads in the skill instructions reference external, non-whitelisted domains for loading remote images, creating iframes, and performing meta-refresh redirects.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 05:46 AM
Security Audit — agent-trust-hub — HTML Injection Testing