hunt-xss
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEOBFUSCATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [OBFUSCATION]: The skill contains a Base64-encoded string
YWxlcnQoMSk=within an example payload (eval(atob(...))). This is provided as an educational reference for WAF bypass techniques and does not obfuscate the skill's own functional logic. - [COMMAND_EXECUTION]: The instructions include command-line examples using
curl,grep, andbashfor identifying and testing XSS reflections. These are standard templates for security auditing and do not perform unauthorized actions. - [EXTERNAL_DOWNLOADS]: The skill references the use of Out-of-Band (OOB) interactions via
oastify.com(Burp Collaborator) for blind XSS detection, which is a common and standard practice in security testing.
Audit Metadata