Cross-Site Scripting and HTML Injection Testing
Detect and exploit stored, reflected, and DOM-based XSS and HTML injection flaws.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for Cross-Site Scripting and HTML Injection Testing, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
An Agent Skill (author zebbern) for client-side injection assessment: identifying and exploiting XSS and HTML injection across stored, reflected, and DOM-based vectors, plus cookie theft, session hijacking, and CSP bypass. It validates input sanitization and output encoding, driving the agent's offensive web testing.
Key features and capabilities
- Stored/reflected/DOM XSS techniques
- Cookie theft and session hijacking
- CSP-bypass and encoding validation
Use cases
- Testing web apps for XSS
- Validating output-encoding defenses