hunt-dom - Analyze client-side DOM attack surfaces
Analyzes DOM clobbering, postMessage, service worker, and CSS injection paths for authorized security assessments.
Tags
Updated: 2026-10-05Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Identify DOM clobbering sinks
- Inspect postMessage origin checks
- Assess service worker abuse paths
- Analyze CSS exfiltration vectors
- Review client-side injection points
- Validate proof-of-concept behavior
Inputs
- Target URL or resource
- Authorized target scope
- Written authorization
- Application source or recon files
- Relevant testing tools
Outputs
- Security assessment findings
- Proof-of-concept evidence
- Command and console results
- Defensive guidance
Requirements
- Explicit written authorization
- Permitted testing scope
- Relevant testing tools
- Sandbox or controlled lab preferred
