hunt-html-injection

SKILLWorkflowcommunauté
v0.0.0elementalsoulsMITMis à jour il y a 1 moisSource →

Hunt HTML Injection — user-supplied input is rendered as raw HTML in the response without sanitisation, allowing an attacker to inject arbitrary HTML tags (but not necessarily JavaScript). Lower severity than XSS but enables phishing, UI manipulation, and credential harvesting via injected forms. Us

Community-submitted skill. Not yet reviewed by the Forge team. Full prompt content may not be available.Request review →
4kÉtoiles du dépôt
1Clients
1Formats
il y a 1 moisDernière mise à jour
Skill
Auteurelementalsouls
Version0.0.0
LicenceMIT
CatégorieWorkflow
Formatsskill.md
PromptOuvrir (voir l’onglet Prompt)
Compatibilité
Claude✓ Pris en charge
Cursor—
Copilot—
ChatGPT—
Gemini—
À propos

Hunt HTML Injection — user-supplied input is rendered as raw HTML in the response without sanitisation, allowing an attacker to inject arbitrary HTML tags (but not necessarily JavaScript). Lower severity than XSS but enables phishing, UI manipulation, and credential harvesting via injected forms. Use when testing text-display surfaces (search results, profile fields, comments, error messages, feed

Mots-clés
skillclaude

Aucune couverture des dépendances

Cette entrée ne publie aucun paquet npm : Forge n'a donc pas d'arbre de dépendances pour elle. C'est une lacune de couverture — pas une affirmation qu'elle n'a aucune dépendance.