offensive-xss
Cross-Site Scripting testing checklist: stored/reflected/DOM/blind XSS discovery, polyglot payloads, CSP bypass, XSS filter bypass, event handler injection, DOM clobbering, mutation XSS, and impact escalation (session hijack, phishing, keylogging). Use for web app XSS testing and bug bounty. Use when performing authorized red-team, pentest, or research work involving xss.
- Compatibility
- claude-code codex opencode
Pinned to revision 626b01ddea63, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/offensive-xss/SKILL.md
- skills/offensive-xss/LICENSE
- skills/offensive-xss/README.md
- skills/offensive-xss/agents/openai.yaml
Every link opens the file at its source, pinned to the revision this page describes.