LogoClawIndex
CasesSkillsAbout
LogoClawIndex

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.

xss-hunter - Test and document cross-site scripting vulnerabilities

Provides a methodology for testing reflected, stored, DOM-based, blind, mutation XSS, CSP bypasses, DOM clobbering, filter evasion, and impact.

Tags

Updated: 2026-10-06

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Identify injection contexts
  • Test reflected XSS
  • Test stored XSS
  • Trace DOM XSS flows
  • Test blind XSS callbacks
  • Evaluate CSP bypasses
  • Test filter evasion
  • Assess mutation XSS
  • Test DOM clobbering
  • Document impact evidence

Inputs

  • Target application URL
  • Injection point
  • Reflected HTML or JavaScript
  • Request parameters and headers
  • Form and API fields
  • Uploaded file content
  • Out-of-band callback endpoint

Outputs

  • Observed XSS execution
  • Out-of-band callback
  • Captured test evidence
  • Impact assessment
  • Remediation guidance

Requirements

  • Web browser with developer tools
  • HTTP testing tools
  • JavaScript-capable test environment

Source

  • Spec: SKILL.md
pentest
xss
web
csp-bypass
dom-clobbering
waf-evasion
bug-bounty
Identify injection contexts
Test reflected XSS
Test stored XSS
Trace DOM XSS flows
Target application URL
Injection point
Reflected HTML or JavaScript
Observed XSS execution
Out-of-band callback
Captured test evidence