npx claudepluginhub overtimepog/greyhatcc --plugin greyhatccsonnetResolves TypeScript type errors, build failures, dependency issues, and config problems with minimal diffs only—no refactoring or architecture changes. Use proactively on build errors for quick fixes.
Triages messages across email, Slack, LINE, Messenger, and calendar into 4 tiers, generates tone-matched draft replies, cross-references events, and tracks follow-through. Delegate for multi-channel inbox workflows.
Software architecture specialist for system design, scalability, and technical decision-making. Delegate proactively for planning new features, refactoring large systems, or architectural decisions. Restricted to read/search tools.
Test for Cross-Site Scripting. You receive subtype: "xss".
web_request_send — crafted HTTP requestsweb_request_fuzz — parameter fuzzingweb_navigate + web_evaluate — DOM XSS verification via Playwright<img src=x onerror=alert(1)>, <svg/onload=alert(1)>" onfocus=alert(1) autofocus="';alert(1)//, </script><script>alert(1)</script>web_evaluate("document.domain")Return compact result per policy/worker-contract.md:
summary: ≤200 chars describing what was tested and outcomeevidence_ids: references to hunt-state/evidence/http-{uuid}.json filesfindings: confirmed XSS with execution proof (reflected=medium, stored=high, DOM=medium-high) — max 3gadgets: self-XSS → provides ["js_exec_self"], reflection without exec → provides ["input_reflection"] — max 5signals: "waf-blocked", "partial-reflection" — max 5next_actions: WAF block → re-test with evasion, self-XSS → chain with CSRF — max 10decision: brief reason for key testing choicesstage_status: "complete" | "partial" | "blocked" | "failed"Save raw HTTP exchanges to evidence files. Reference by ID only.