payloads-xss-polyglots

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEOBFUSCATION
Full Analysis
  • [OBFUSCATION]: The skill includes a cross-site scripting (XSS) polyglot payload that uses multiple encoding methods to evade security controls. Evidence: The payload in SKILL.md uses hex encoding (\x3c for < and \x3e for >) and URL encoding (%0D%0A for line breaks) within the polyglot string to evade context-based detection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 11:02 PM
Security Audit — agent-trust-hub — payloads-xss-polyglots