html-injection-testing
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is an educational resource for web application security testing. It provides transparent examples of HTML injection payloads and testing workflows for security professionals.
- [DYNAMIC_EXECUTION]: Contains a Python script in Phase 9 intended for manual fuzzing of web parameters. The script utilizes the
requestslibrary to automate the testing of a list of HTML payloads against a target URL provided by the user. This is a standard utility for vulnerability assessment. - [EXTERNAL_DOWNLOADS]: Reference URLs such as
attacker.comandtarget.comare used as placeholders throughout the documentation to demonstrate attack scenarios and phishing forms. These do not represent real-world malicious infrastructure or automated callbacks. - [COMMAND_EXECUTION]: Includes several
curlcommand examples (Phase 3 and 4) to teach users how to manually test for reflected HTML content. These commands are documented for educational purposes and are not executed automatically by the skill.
Audit Metadata