dangling-markup-injection
Warn
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: MEDIUMPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill provides explicit instructions to bypass common web security mechanisms such as Content Security Policy (CSP), HTML sanitizers, and Web Application Firewalls (WAF). It instructs the agent that when JavaScript execution is blocked, 'dangling markup is the answer,' effectively teaching the agent how to circumvent established safety boundaries.
- [DATA_EXFILTRATION]: The skill contains detailed blueprints for exfiltrating sensitive data, including CSRF tokens, session identifiers, PII, and API keys, to an external attacker-controlled domain (attacker.com). It describes using various HTML tags (e.g., img, form, base, meta, link) to capture and transmit page content.
- [DATA_EXFILTRATION]: It details advanced techniques for data theft, such as 'Form Action Hijack' and 'Base Tag Hijack,' which can be used to redirect sensitive user data and form submissions to external third-party servers.
Audit Metadata