TacoSkill LABTacoSkill LAB

The full-lifecycle AI skills platform.

Product

  • SkillHub
  • Playground
  • Skill Create
  • SkillKit

Resources

  • Privacy
  • Terms
  • About

Platforms

  • Claude Code
  • Cursor
  • Codex CLI
  • Gemini CLI
  • OpenCode

© 2026 TacoSkill LAB. All rights reserved.

TacoSkill LAB
TacoSkill LAB
HomeSkillHubCreatePlaygroundSkillKit
  1. Home
  2. /
  3. SkillHub
  4. /
  5. Cross-Site Scripting and HTML Injection Testing
Improve

Cross-Site Scripting and HTML Injection Testing

8.1

by davila7

189Favorites
405Upvotes
0Downvotes

This skill should be used when the user asks to "test for XSS vulnerabilities", "perform cross-site scripting attacks", "identify HTML injection flaws", "exploit client-side injection vulnerabilities", "steal cookies via XSS", or "bypass content security policies". It provides comprehensive techniques for detecting, exploiting, and understanding XSS and HTML injection attack vectors in web applications.

xss-testing

8.1

Rating

0

Installs

Security

Category

Quick Review

This is a comprehensive and well-structured XSS/HTML injection testing skill with excellent task knowledge. The description clearly covers when to invoke the skill with specific trigger phrases. The content provides extensive payloads, techniques, bypass methods, and practical examples that would be difficult for a CLI agent to generate from scratch. The structure is logical with clear phases, quick reference tables, and troubleshooting guidance. The skill demonstrates strong technical depth across stored, reflected, and DOM-based XSS variants, plus filter bypass techniques and CSP evasion. Novelty is moderate as XSS testing is a well-established domain, but the comprehensive payload collection, bypass techniques, and structured workflow do provide meaningful value over ad-hoc CLI attempts. Minor improvement areas: the SKILL.md is somewhat lengthy and could potentially benefit from splitting advanced bypass techniques into separate reference files, though the current single-file approach remains manageable and well-organized with clear sections.

LLM Signals

Description coverage9
Task knowledge10
Structure8
Novelty6

GitHub Signals

18,239
1,655
133
73
Last commit 0 days ago

Publisher

davila7

davila7

Skill Author

Related Skills

secure-code-guardiansecurity-reviewerrepomix-safe-mixer

Loading SKILL.md…

Try onlineView on GitHub

Publisher

davila7 avatar
davila7

Skill Author

Related Skills

secure-code-guardian

Jeffallan

6.4

security-reviewer

Jeffallan

6.4

repomix-safe-mixer

daymade

7.4

iotnet

BrownFineSecurity

6.3
Try online