From xss-vulnerability-scanner
Scans codebases for reflected, stored, DOM-based XSS in HTML, JavaScript, CSS, URLs; tests WAF bypass and CSP. Activates on 'scan for XSS' or '/xss'.
npx claudepluginhub jeremylongshore/claude-code-plugins-plus-skills --plugin xss-vulnerability-scannerThis skill is limited to using the following tools:
Detect reflected, stored, and DOM-based XSS vulnerabilities through context-aware analysis of HTML, JavaScript, CSS, and URL injection points, with WAF bypass testing and CSP evaluation.
Guides web app penetration testing for XSS vulnerabilities including stored, reflected, DOM-based attacks, payloads, filter bypasses, CSP evasion, and detection checklists.
Tests web apps for reflected, stored, and DOM-based XSS by injecting payloads, mapping inputs/outputs, and bypassing sanitization/CSP protections.
Tests web applications for reflected, stored, and DOM-based XSS vulnerabilities by injecting JavaScript payloads, identifying injection points, and bypassing sanitization or CSP protections. For OWASP security testing.
Share bugs, ideas, or general feedback.
Detect reflected, stored, and DOM-based XSS vulnerabilities through context-aware analysis of HTML, JavaScript, CSS, and URL injection points, with WAF bypass testing and CSP evaluation.
This skill empowers Claude to proactively identify and report XSS vulnerabilities within your codebase. By leveraging advanced detection techniques, including context-aware analysis and WAF bypass testing, this skill ensures your web applications are resilient against common XSS attack vectors. It provides detailed insights into vulnerability types and offers guidance on remediation strategies.
This skill activates when you need to:
User request: "scan for XSS vulnerabilities in the search functionality"
The skill will:
User request: "/xss check the comment submission form"
The skill will:
sanitizeHtml.This skill complements other security-focused plugins by providing targeted XSS vulnerability detection. It can be integrated with code review tools to automate security checks and provide developers with immediate feedback on potential XSS issues.
The skill produces structured output relevant to the task.