Laporan audit skill
hunt-dom Laporan audit.
Hunt client-side DOM vulnerabilities — DOM Clobbering (overwrite JS globals via HTML injection), PostMessage hijacking (missing origin check), Service Worker abuse (intercept requests from same-origin script), CSS Injection/Exfiltration (attribute selectors → token char-by-char via OOB), client-side template injection, dangerouslySetInnerHTML. Grounded in named public research: Gareth Heyes / PortSwigger DOM-clobbering + DOM-Invader, Michał Bentkowski DOMPurify clobbering bypasses, jQuery htmlPrefilter XSS (CVE-2020-11022 / CVE-2020-11023), d0nut CSS-exfil research. Use when hunting DOM-XSS, client-side auth bypass, or token exfiltration without server-side interaction.
Trust Score OpenAgentSkill
Trust Score OpenAgentSkill
The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.
Adopsi GitHub
Lulus86
4.3K star GitHub
Aktivitas star/fork
Lulus83
4.3K star dan 654 fork; aktivitas issue tidak tersedia dalam metadata saat ini
Pemeliharaan terbaru
Lulus88
1 bulan sejak push
Kejelasan lisensi
Lulus86
MIT
Kelengkapan README/SKILL.md
Lulus86
Metadata memuat konteks penggunaan dan alur kerja yang cukup
Risiko dependensi/runtime
Peringatan46
command execution surface, credential or environment access
Ketersediaan pemasangan
Lulus92
npx skills add elementalsouls/Claude-BugHunter --skill hunt-dom
Keamanan perintah pemasangan
Lulus92
Jalur pemasangan paket atau runtime standar
Cakupan izin
Gagal22
secrets or environment access, shell or command execution
Bukti repositori
Lulus86
https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-dom
Status peninjauan
Info66
Data tinjauan AI tersedia
Hasil terbukti Agent
Info54
Belum ada data hasil Agent
Pemeriksaan
Tinjauan pemasangan dan adopsi
Jalur pemasangan
92
npx skills add elementalsouls/Claude-BugHunter --skill hunt-dom
Repositori
88
https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-dom
Lisensi
86
MIT
Pemeliharaan
88
1 bulan sejak push
Tinjauan AI
55
The excerpt does not explicitly state authorization requirements or responsible disclosure guidelines, which are critical for offensive security skills.
Kelengkapan README/SKILL.md
86
Usable description available
Risiko dependensi
46
command execution surface, credential or environment access
Keamanan perintah pemasangan
92
Jalur pemasangan paket atau runtime standar
Cakupan izin
22
secrets or environment access, shell or command execution
Aktivitas star/fork
83
4.3K star dan 654 fork; aktivitas issue tidak tersedia dalam metadata saat ini
Adopsi
88
4.3K star GitHub
Financial decision safety
58
Research-only use: do not treat output as financial advice or execute a position without human approval.
Peringatan
- Dependency or permission surface needs review
- Permission surface may require sandboxing
- Financial research output is not financial advice; require human review before any live investment decision
- The excerpt does not explicitly state authorization requirements or responsible disclosure guidelines, which are critical for offensive security skills.
- The skill description mentions 'report_count: 14' but does not clarify if these are internal metrics or external references; this could be ambiguous.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
Metode
This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.
Bandingkan opsi sekitar
Skill terkait untuk diaudit berikutnya
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16K Star · Laporan audit
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
33K Star · Laporan audit
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29K Star · Laporan audit