LogoClawIndex
CasesSkillsAbout
LogoClawIndex

hunt-dom - Analyze client-side DOM attack surfaces

Analyzes DOM clobbering, postMessage, service worker, and CSS injection paths for authorized security assessments.

Tags

Updated: 2026-10-05

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Identify DOM clobbering sinks
  • Inspect postMessage origin checks
  • Assess service worker abuse paths
  • Analyze CSS exfiltration vectors
  • Review client-side injection points
  • Validate proof-of-concept behavior

Inputs

  • Target URL or resource
  • Authorized target scope
  • Written authorization
  • Application source or recon files
  • Relevant testing tools

Outputs

  • Security assessment findings
  • Proof-of-concept evidence
  • Command and console results
  • Defensive guidance

Requirements

  • Explicit written authorization
  • Permitted testing scope
  • Relevant testing tools
  • Sandbox or controlled lab preferred

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
web security
client-side security
DOM clobbering
postMessage
service workers
CSS exfiltration
Identify DOM clobbering sinks
Inspect postMessage origin checks
Assess service worker abuse paths
Analyze CSS exfiltration vectors
Target URL or resource
Authorized target scope
Written authorization
Security assessment findings
Proof-of-concept evidence
Command and console results