dom-xss
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The content is purely educational and descriptive, focusing on security testing methodologies and defensive coding practices for DOM XSS.
- [SAFE]: While the skill contains examples of XSS payloads (e.g., using
alert(1)ordocument.cookie), these are clearly presented as diagnostic examples within markdown code blocks for learning and testing purposes, not as instructions for the agent to execute maliciously. - [SAFE]: The skill does not include any scripts, configuration for automated tools, or network-enabled components. It relies on the user or agent manually reviewing code or using third-party browser tools.
- [SAFE]: The external references provided, such as OWASP, are trusted industry standards for security documentation.
Audit Metadata