xss-hunter - Test and document cross-site scripting vulnerabilities
Provides a methodology for testing reflected, stored, DOM-based, blind, mutation XSS, CSP bypasses, DOM clobbering, filter evasion, and impact.
Tags
Updated: 2026-10-06Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Identify injection contexts
- Test reflected XSS
- Test stored XSS
- Trace DOM XSS flows
- Test blind XSS callbacks
- Evaluate CSP bypasses
- Test filter evasion
- Assess mutation XSS
- Test DOM clobbering
- Document impact evidence
Inputs
- Target application URL
- Injection point
- Reflected HTML or JavaScript
- Request parameters and headers
- Form and API fields
- Uploaded file content
- Out-of-band callback endpoint
Outputs
- Observed XSS execution
- Out-of-band callback
- Captured test evidence
- Impact assessment
- Remediation guidance
Requirements
- Web browser with developer tools
- HTTP testing tools
- JavaScript-capable test environment
