client-side

Installation
SKILL.md

Client-Side

Test for client-side vulnerabilities across modern web applications and SPAs.

Techniques

Type Key Vectors
XSS Reflected, Stored, DOM-based, framework-specific (React, Vue, Angular)
CSRF Token bypass, SameSite cookie bypass, cross-origin requests
CORS Misconfigured origins, null origin, wildcard credentials
Clickjacking Frame-based, drag-and-drop, multi-step
DOM-based DOM sinks, source/sink analysis, JavaScript URL schemes
Prototype Pollution Client-side gadgets, server-side pollution, property injection

Workflow

  1. Identify input sources and data flows
  2. Classify sink contexts (HTML, attribute, URL, JS, CSS)
Related skills
Installs
36
GitHub Stars
258
First Seen
Mar 21, 2026