Install
1
Install the plugin$
npx claudepluginhub diegouis/provectus-marketplace --plugin proagent-securityWant just this command?
Then install: npx claudepluginhub u/[userId]/[slug]
Description
Scan frontend code for cross-site scripting vulnerabilities (reference: `agents/plugins/frontend-mobile-security/commands/xss-scan.md`).
Namespace
modes/Command Content
XSS Scan — Frontend XSS Vulnerability Scan
Scan frontend code for cross-site scripting vulnerabilities (reference: agents/plugins/frontend-mobile-security/commands/xss-scan.md).
Steps:
- Detect frontend framework:
- Identify React, Vue, Angular, Svelte, or vanilla JS from package.json and imports
- Check for server-side rendering (Next.js, Nuxt, SvelteKit)
- Scan for DOM-based XSS:
- Search for
innerHTML,outerHTML,document.write,document.writeln - Search for
dangerouslySetInnerHTML(React),v-html(Vue),[innerHTML](Angular) - Search for
eval(),Function(),setTimeout(string),setInterval(string) - Check for unsanitized URL parameters used in DOM manipulation
- Search for
- Scan for reflected XSS:
- Check error messages and search results for unescaped user input
- Verify template engines use auto-escaping by default
- Check for raw output directives (
{!! !!}in Blade,| safein Jinja2,<%- %>in EJS)
- Verify security headers:
- Check Content-Security-Policy blocks
unsafe-inlineandunsafe-eval - Verify X-Content-Type-Options is set to
nosniff - Check Referrer-Policy configuration
- Check Content-Security-Policy blocks
- Generate XSS report:
- Categorize findings by severity and XSS type (stored, reflected, DOM-based)
- Provide framework-specific remediation (use DOMPurify, sanitize-html, etc.)
- Recommend CSP configuration updates
Stats
Stars2
Forks1
Last CommitMar 12, 2026