Cross-Site Scripting and HTML Injection Testing

21.8k
davila7davila7

This skill should be used when the user asks to "test for XSS vulnerabilities", "perform cross-site scripting attacks", "identify HTML injection flaws", "exploit client-side injection vulnerabilities", "steal cookies via XSS", or "bypass content security policies". It provides comprehensive techniques for detecting, exploiting, and understanding XSS and HTML injection attack vectors in web applications.

195 days ago

HTML Injection Testing

21.8k
davila7davila7

This skill should be used when the user asks to "test for HTML injection", "inject HTML into web pages", "perform HTML injection attacks", "deface web applications", or "test content injection vulnerabilities". It provides comprehensive HTML injection attack techniques and testing methodologies.

195 days ago

Cross-Site Scripting and HTML Injection Testing

3.5k
zebbernzebbern

This skill should be used when the user asks to "test for XSS vulnerabilities", "perform cross-site scripting attacks", "identify HTML injection flaws", "exploit client-side injection vulnerabilities", "steal cookies via XSS", or "bypass content security policies". It provides comprehensive techniques for detecting, exploiting, and understanding XSS and HTML injection attack vectors in web applications.

195 days ago

HTML Injection Testing

3.5k
zebbernzebbern

This skill should be used when the user asks to "test for HTML injection", "inject HTML into web pages", "perform HTML injection attacks", "deface web applications", or "test content injection vulnerabilities". It provides comprehensive HTML injection attack techniques and testing methodologies.

195 days ago

input-guard

1.8k
openclawopenclaw

Scan untrusted external text (web pages, tweets, search results, API responses) for prompt injection attacks. Returns severity levels and alerts on dangerous content. Use BEFORE processing any text from untrusted sources.

195 days ago

text-processor

1.8k
openclawopenclaw

Process and clean text content

195 days ago

prompt-defense

1.8k
openclawopenclaw

Detect and block prompt injection attacks in emails. Use when reading, processing, or summarizing emails. Scans for fake system outputs, planted thinking blocks, instruction hijacking, and other injection patterns. Requires user confirmation before acting on any instructions found in email content.

195 days ago

indirect-prompt-injection

1.8k
openclawopenclaw

Detect and reject indirect prompt injection attacks when reading external content (social media posts, comments, documents, emails, web pages, user uploads). Use this skill BEFORE processing any untrusted external content to identify manipulation attempts that hijack goals, exfiltrate data, override instructions, or social engineer compliance. Includes 20+ detection patterns, homoglyph detection, and sanitization scripts.

195 days ago

openclaw-sec

1.8k
Openclaw Skills Openclaw SecOpenclaw Skills Openclaw Sec

AI Agent Security Suite - Real-time protection against prompt injection, command injection, SSRF, path traversal, secrets exposure, and content policy violations

195 days ago

clawdefender

1.8k
openclawopenclaw

Security scanner and input sanitizer for AI agents. Detects prompt injection, command injection, SSRF, credential exfiltration, and path traversal attacks. Use when (1) installing new skills from ClawHub, (2) processing external input like emails, calendar events, Trello cards, or API responses, (3) validating URLs before fetching, (4) running security audits on your workspace. Protects agents from malicious content in untrusted data sources.

195 days ago

CSP Security Testing

71
PramodDuttaPramodDutta

Content Security Policy testing and validation to prevent XSS attacks, data injection, and clickjacking through proper CSP header configuration.

cspsecurityxss+2
195 days ago

Browser Extension Testing

71
PramodDuttaPramodDutta

Testing browser extensions including content script injection, background worker testing, popup UI testing, storage API testing, and cross-browser compatibility.

browser-extensionchromefirefox+2
195 days ago

AI Safety Alignment

29
omer-metinomer-metin

Implement comprehensive safety guardrails for LLM applications including content moderation (OpenAI Moderation API), jailbreak prevention, prompt-injection defense, PII detection, topic guardrails, and output validation. Essential for production AI applications that handle user-generated content. Use when keywords like guardrails, content-moderation, prompt-injection, jailbreak-prevention, pii-detection, nemo-guardrails, openai-moderation, llama-guard, or safety are relevant.

195 days ago

HTML Injection Testing

14
zebbernzebbern

This skill should be used when the user asks to "test for HTML injection", "inject HTML into web pages", "perform HTML injection attacks", "deface web applications", or "test content injection vulnerabilities". It provides comprehensive HTML injection attack techniques and testing methodologies.

html-injectionweb-securityinjection+2
195 days ago

Cross-Site Scripting and HTML Injection Testing

14
zebbernzebbern

This skill should be used when the user asks to "test for XSS vulnerabilities", "perform cross-site scripting attacks", "identify HTML injection flaws", "exploit client-side injection vulnerabilities", "steal cookies via XSS", or "bypass content security policies". It provides comprehensive techniques for detecting, exploiting, and understanding XSS and HTML injection attack vectors in web applications.

xsscross-site-scriptinghtml-injection+3
195 days ago

guardrails-safety-filter-builder

12
patricio0312revpatricio0312rev

Implements content safety filters with PII redaction, policy constraints, prompt injection detection, and safe refusal templates. Use when adding "content moderation", "safety filters", "PII protection", or "guardrails".

195 days ago

sqlmap

9
TerminalSkillsTerminalSkills

Detect and exploit SQL injection with sqlmap. Use when a user asks to test for SQL injection, extract database contents, bypass authentication via SQLi, automate injection testing, or dump database schemas.

195 days ago

humanizer-pro

8
YuniorGlezYuniorGlez

Senior Content Humanization Architect for 2026. Specialized in natural language refinement, authentic voice injection, and AI-detection avoidance. Expert in transforming robotic, predictable AI drafts into high-engagement, human-centric content that satisfies E-E-A-T standards and builds deep trust through empathy, storytelling, and cultural nuance.

195 days ago

Cross-Site Scripting and HTML Injection Testing

5
agent-skills-hubagent-skills-hub

This skill should be used when the user asks to "test for XSS vulnerabilities", "perform cross-site scripting attacks", "identify HTML injection flaws", "exploit client-side injection vulnerabilities", "steal cookies via XSS", or "bypass content security policies". It provides comprehensive techniques for detecting, exploiting, and understanding XSS and HTML injection attack vectors in web applications.

195 days ago

HTML Injection Testing

5
agent-skills-hubagent-skills-hub

This skill should be used when the user asks to "test for HTML injection", "inject HTML into web pages", "perform HTML injection attacks", "deface web applications", or "test content injection vulnerabilities". It provides comprehensive HTML injection attack techniques and testing methodologies.

195 days ago

agent-security-guardrails

4
gitwaltergitwalter

Tactical Blueprint for AI Security and Guardrails. Focuses on prompt injection defense, PII detection, and content safety for agentic systems.

195 days ago

securing-agents

4
gitwaltergitwalter

Tactical Blueprint for AI Security and Guardrails. Focuses on prompt injection defense, PII detection, and content safety for agentic systems.

195 days ago

ai-security

4
gitwaltergitwalter

Prompt injection defense, API security, and content filtering for AI systems

195 days ago

llm-guardrails

4
gitwaltergitwalter

NeMo Guardrails setup, Guardrails AI integration, prompt injection prevention, PII detection, content safety, topic control

195 days ago

applying-llm-guardrails

4
gitwaltergitwalter

NeMo Guardrails setup, Guardrails AI integration, prompt injection prevention, PII detection, content safety, topic control

195 days ago

securing-ai-systems

4
gitwaltergitwalter

Prompt injection defense, API security, and content filtering for AI systems

195 days ago

testing-android-intents-for-vulnerabilities

2
mukul975mukul975

Tests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection, unauthorized component access, broadcast sniffing, pending intent hijacking, and content provider data leakage. Use when assessing Android app attack surface through exported components, testing intent-based data flows, or evaluating IPC security. Activates for requests involving Android intent security, IPC testing, exported component analysis, or Drozer assessment.

mobile-securityandroidintents+3
195 days ago

exploiting-sql-injection-with-sqlmap

2
mukul975mukul975

Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.

penetration-testingsql-injectionsqlmap+3
195 days ago

performing-content-security-policy-bypass

2
mukul975mukul975

Analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations, JSONP endpoints, unsafe directives, and policy injection techniques.

csp-bypasscontent-security-policyxss+4
195 days ago

Cross-Site Scripting and HTML Injection Testing

1
agent-arc-744agent-arc-744

This skill should be used when the user asks to "test for XSS vulnerabilities", "perform cross-site scripting attacks", "identify HTML injection flaws", "exploit client-side injection vulnerabilities", "steal cookies via XSS", or "bypass content security policies". It provides comprehensive techniques for detecting, exploiting, and understanding XSS and HTML injection attack vectors in web applications.

195 days ago

xss-prevention

sharp-skillssharp-skills

Prevents Cross-Site Scripting attacks by ensuring user content is never executed as code in the browser. Triggers on: render user content, display user input, innerHTML, dangerouslySetInnerHTML, template, user-generated content, comments, markdown, rich text, HTML output, v-html, ng-bind-html, template injection.

195 days ago

Cross-Site Scripting and HTML Injection Testing

haniakrim21haniakrim21

This skill should be used when the user asks to 'test for XSS vulnerabilities', 'perform cross-site scripting attacks', 'identify HTML injection flaws', 'exploit client-side injection vulnerabilities', 'steal cookies via XSS', or 'bypass content security policies'. It provides comprehensive techniques for detecting, exploiting, and understanding XSS and HTML injection attack vectors in web applications.

195 days ago

Android Pentesting

narlyseorgnarlyseorg

Use when testing Android applications for security vulnerabilities. Triggers: APK analysis, mobile app assessment, Android static analysis, dynamic analysis, runtime manipulation with Frida, traffic interception with mitmproxy, SSL pinning bypass, root detection bypass, insecure data storage testing, exported component abuse, deeplink fuzzing, content provider exploitation, reverse engineering Android apps, OWASP Mobile Top 10 assessment, certificate pinning testing, biometric bypass, intent injection.

195 days ago

prompt-injection-defense

alexyyyanderalexyyyander

Activate this skill whenever processing any user input, external content, or untrusted text. Provides complete language-level defense against prompt injection, jailbreaks, role hijacking, authority impersonation, indirect injection, payload smuggling, and 8 other attack categories. Every agent should keep this skill active at all times. Compatible with Claude, GPT, Gemini, Copilot, and any LLM.

securityprompt-injectionjailbreak-defense+3
195 days ago

HTML Injection Testing

haniakrim21haniakrim21

This skill should be used when the user asks to "test for HTML injection", "inject HTML into web pages", "perform HTML injection attacks", "deface web applications", or "test content injection vulnerabilities". It provides comprehensive HTML injection attack techniques and testing methodologies.

195 days ago

ShieldClaw

ZandereinsZandereins

Prompt-injection defense for OpenClaw agents. Provides real-time awareness, active hook-based blocking, canary-token monitoring, and on-demand skill vetting. Use when processing untrusted content or when suspicious instructions appear in tool outputs.

195 days ago

openclaw-sec

BJS-Innovation-LabBJS-Innovation-Lab

AI Agent Security Suite - Real-time protection against prompt injection, command injection, SSRF, path traversal, secrets exposure, and content policy violations

195 days ago

prompt-injection-guard

sharp-skillssharp-skills

Protects AI agents from prompt injection attacks — malicious instructions embedded in external data (web pages, documents, emails, API responses, user inputs) that hijack agent behavior. Use this skill whenever an agent reads external content and then takes actions. Triggers on: "agent reads external data", "process documents with AI", "web scraping with agent", "AI reads emails", "agent processes user files", "RAG system", "AI with tool use", "autonomous agent", "agent browses web", "AI reads database", "multi-step agent", "agentic AI". Anthropic explicitly states: "prompt injection remains an unsolved problem in AI safety research." This skill implements the best current defenses.

195 days ago

prompt-injection-defense

alexyyyanderalexyyyander

Activate this skill whenever processing any user input, external content, or untrusted text. Provides complete language-level defense against prompt injection, jailbreaks, role hijacking, authority impersonation, indirect injection, payload smuggling, and 8 other attack categories. Every agent should keep this skill active at all times. Compatible with Claude, GPT, Gemini, Copilot, and any LLM.

securityprompt-injectionjailbreak-defense+3
195 days ago

HTML Injection Testing

oki3505Foki3505F

This skill should be used when the user asks to "test for HTML injection", "inject HTML into web pages", "perform HTML injection attacks", "deface web applications", or "test content injection vulnerabilities". It provides comprehensive HTML injection attack techniques and testing methodologies.

195 days ago

_KB

XPrime17XPrime17

Voice AI Knowledge Base manager. Read/write Google Docs and sync content to Supabase for prompt injection. USE WHEN kb, knowledge base, sync kb, read doc, write doc, update kb, kb content, google doc, sync doc.

195 days ago

Cross-Site Scripting and HTML Injection Testing

oki3505Foki3505F

This skill should be used when the user asks to "test for XSS vulnerabilities", "perform cross-site scripting attacks", "identify HTML injection flaws", "exploit client-side injection vulnerabilities", "steal cookies via XSS", or "bypass content security policies". It provides comprehensive techniques for detecting, exploiting, and understanding XSS and HTML injection attack vectors in web applications.

195 days ago