html-injection-testing

Fail

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill provides detailed templates for phishing attacks designed to steal user credentials. Specifically, it includes HTML payloads for fake login form overlays that POST sensitive data to attacker-controlled domains.
  • [DATA_EXFILTRATION]: It contains techniques for exfiltrating session cookies by using CSS injection to send document.cookie data to external servers via background image URL requests.
  • [COMMAND_EXECUTION]: The skill includes a functional Python fuzzing script that utilizes the requests library to automate the probing of web parameters for injection vulnerabilities.
  • [DATA_EXFILTRATION]: Multiple payloads are provided for 'Stored HTML Injection' and 'Reflected POST Injection' specifically aimed at harvesting user input and sending it to external endpoints like attacker.com or evil.com.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 9, 2026, 09:25 PM
Security Audit — agent-trust-hub — html-injection-testing