OpenAgentSkill Registry Manifest Skill: hunt-dom Slug: elementalsouls-hunt-dom Category: security Description: Hunt client-side DOM vulnerabilities — DOM Clobbering (overwrite JS globals via HTML injection), PostMessage hijacking (missing origin check), Service Worker abuse (intercept requests from same-origin script), CSS Injection/Exfiltration (attribute selectors → token char-by-char via OOB), client-side template injection, dangerouslySetInnerHTML. Grounded in named public research: Gareth Heyes / PortSwigger DOM-clobbering + DOM-Invader, Michał Bentkowski DOMPurify clobbering bypasses, jQuery htmlPrefilter XSS (CVE-2020-11022 / CVE-2020-11023), d0nut CSS-exfil research. Use when hunting DOM-XSS, client-side auth bypass, or token exfiltration without server-side interaction. Agent fit: - Decision: 94/100 Production-ready - Primary fit: GitHub automation - Role: Primary pick Supply profile: - Track: Coding and developer agents - Scenario: GitHub automation - Applicable agents: Claude Code, Browser agents, CLI, Codex, Cursor - Maintenance: 2d since push - Risk: Needs review Trust: - Trust score: 70/100 Manual review - Audit: 80/100 Needs review Attribution: - Status: Registry indexed - Source: recursive skill source sync - Creator: elementalsouls - Claim URL: https://www.openagentskill.com/skills/elementalsouls-hunt-dom#claim-this-skill Install: npx skills add elementalsouls/Claude-BugHunter --skill hunt-dom URLs: - Web: https://www.openagentskill.com/skills/elementalsouls-hunt-dom - API: https://www.openagentskill.com/api/agent/skills/elementalsouls-hunt-dom - Install API: https://www.openagentskill.com/api/skills/elementalsouls-hunt-dom/install - Repository: https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-dom