CtrlK
BlogDocsLog inGet started
Tessl Logo

xss-html-injection

This skill should be used when the user asks to "test for XSS vulnerabilities", "perform cross-site scripting attacks", "identify HTML injection flaws", "exploit client-side injection vulnerabilities", "steal cookies via XSS", or "bypass content security policies". It provides comprehensive techniques for detecting, exploiting, and understanding XSS and HTML injection attack vectors in web applications.

66

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/xss-html-injection/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable and well-sequenced, with excellent executable examples throughout. The weaknesses are a monolithic ~490-line structure with no reference files, and notable redundancy (the cookie-theft payload family repeated four times) plus prerequisite sections that restate knowledge Claude already has.

Suggestions

Move the payload catalogs (Phase 6 filter/encoding bypasses, the Common XSS Payloads table, and the four worked examples) into reference files such as references/payloads.md and references/examples.md, keeping SKILL.md to the workflow overview and detection checklist.

Collapse the four near-duplicate cookie/session-capture payloads (Phase 2, Cookie Theft Payload, Session Hijacking Template, Example 1) into a single canonical exfiltration snippet referenced once.

Trim the 'Inputs/Prerequisites' and 'Technical Requirements' sections to the authorization/scope items that actually gate the work, dropping generic knowledge statements like 'Understanding of JavaScript execution in browser context', and add an explicit post-test cleanup step (removing stored test payloads and captured data) to the core workflow.

DimensionReasoningScore

Conciseness

Much of the body is dense, copy-paste reference material (payload tables, sinks/sources lists) rather than prose padding, but there is real fat: the cookie/session-capture payload appears in essentially the same form four times (Phase 2, 'Cookie Theft Payload', 'Session Hijacking Template', Example 1), and the 'Technical Requirements'/'Inputs' sections restate knowledge Claude already has ('Understanding of JavaScript execution in browser context'). Not 2 because the bulk is reference content, not explanatory filler, but it could be cut substantially.

3 / 5

Actionability

Fully executable throughout: concrete payloads ('<img src=x onerror=alert(1)>'), raw HTTP examples ('POST /api/comments ... {"body": "<script>alert('XSS')</script>"}'), a context-to-payload table, working CSP-bypass JSONP snippets, and a troubleshooting table mapping failure symptoms to specific fixes. Copy-paste ready and covering the common cases.

5 / 5

Workflow Clarity

The six-phase sequence (detect → classify XSS type → stored → reflected → DOM → HTMLi → bypass) is clear, with observation checkpoints ('Monitor for: Raw HTML reflection without encoding...') and a detection checklist in the Quick Reference. Not 5 because there is no explicit validate-and-cleanup step after injecting into shared targets (e.g., removing stored test payloads), which the guardrails gesture at ('Limit cookie/session capture to demonstration purposes') but never sequence as a step.

4 / 5

Progressive Disclosure

Section headers and tables give reasonable structure, but the ~490-line body is monolithic: the payload catalogs (Phase 6 filter bypasses, Common XSS Payloads table), the four full examples, and the troubleshooting matrix all belong in separate reference files, and no bundle files exist. This matches the 3 anchor — 'some structure... content that should be separate is inline' — rather than 2, since structure is present, not minimal.

3 / 5

Total

15

/

20

Passed

Description

86%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with an explicit, well-phrased trigger list and a distinct niche. The only weakness is the mildly buzzwordy 'what' clause ('comprehensive techniques'), which keeps specificity and completeness just below the top anchors.

DimensionReasoningScore

Specificity

The 'what' clause lists several actions — 'detecting, exploiting, and understanding XSS and HTML injection attack vectors' — naming the domain plus multiple capabilities. It falls short of the 5 anchor because the actions are abstract verbs and 'comprehensive techniques' is a buzzword over-claim rather than concrete deliverables, but it clearly exceeds the 1-2-action scope of the 3 anchor.

4 / 5

Completeness

Both clauses are explicit: 'This skill should be used when the user asks to...' answers when, and 'It provides comprehensive techniques for...' answers what. Not 5 because the 'what' leans on the vague 'comprehensive techniques' phrasing rather than concrete capabilities like the 5-anchor example; not 3 because the 'when' is fully explicit, not merely implied.

4 / 5

Trigger Term Quality

Six quoted natural phrases cover the space well with synonyms: 'test for XSS vulnerabilities', 'perform cross-site scripting attacks', 'identify HTML injection flaws', 'exploit client-side injection vulnerabilities', 'steal cookies via XSS', 'bypass content security policies'. These are exactly what a user would say, spanning the abbreviation, the full term, HTML injection, cookie theft, and CSP bypass — nothing meaningful is missing.

5 / 5

Distinctiveness Conflict Risk

It occupies a clear niche (client-side XSS/HTML injection testing) with distinct trigger phrases like 'steal cookies via XSS' and 'bypass content security policies' that would not plausibly fire a general web-security or server-side testing skill.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.