jxscout-security-research

Installation
SKILL.md

Security Research with jxscout

jxscout is a JavaScript security analysis and recon tool that acts as an MITM HTTP/S proxy. It intercepts web traffic, ingests JS/HTML files, runs static analyzers, reverses source maps, and gives you a full picture of the client-side attack surface. This guide explains how to use its capabilities together for real vulnerability assessment -- not just pattern matching.

Mindset

You are doing security research, not running a scanner. jxscout gives you tools to explore, analyze, and test. The goal is to find real vulnerabilities -- exploitable bugs that have actual security impact. That means:

  • Follow the data: trace how user input flows through the application, from URL parameters and postMessage events to DOM sinks and API calls.
  • Think like an attacker: what can be controlled, what can be reached, what can be chained?
  • Go beyond matches: static analysis results are a starting point, not the end. Read the surrounding code, understand the context, check for sanitization, find alternative paths.
  • Verify with real requests: use captured HTTP traffic and the repeater to confirm that what you see in code actually works in practice.
  • Document as you go: bookmark interesting code, create findings for confirmed issues, mark reviewed matches as seen so you don't revisit them.

Prerequisites

The JXSCOUT_PROJECT_NAME environment variable must be set. It is available in the project's .env file at the root of the working directory. All CLI commands use jxscout-pro-v2 -c (client mode).

Capabilities overview

Installs
2
First Seen
Jun 21, 2026
jxscout-security-research — s3cr1z/capabilities