client-side
Client-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution.
How do I install this agent skill?
npx skills add https://github.com/transilienceai/communitytools --skill client-sideIs this agent skill safe to install?
- Gen Agent Trust Hubpass
This skill is a comprehensive security reference and testing toolkit focused on client-side vulnerabilities such as XSS, CSRF, and Prototype Pollution. It contains extensive educational material, exploit payloads, and detection scripts designed to help security professionals identify and remediate these issues. While the skill includes patterns typically associated with malicious behavior (such as RCE payloads and exfiltration scripts), these are presented solely as reference material for vulnerability validation and do not pose a threat in the context of the skill's intended purpose.
- Socketfail
23 alerts: gptSecurity, gptMalware
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Client-Side
Test for client-side vulnerabilities across modern web applications and SPAs.
Techniques
| Type | Key Vectors |
|---|---|
| XSS | Reflected, Stored, DOM-based, framework-specific (React, Vue, Angular) |
| CSRF | Token bypass, SameSite cookie bypass, cross-origin requests |
| CORS | Misconfigured origins, null origin, wildcard credentials |
| Clickjacking | Frame-based, drag-and-drop, multi-step |
| DOM-based | DOM sinks, source/sink analysis, JavaScript URL schemes |
| Prototype Pollution | Client-side gadgets, server-side pollution, property injection |
Workflow
- Identify input sources and data flows
- Classify sink contexts (HTML, attribute, URL, JS, CSS)
- Enumerate defenses (encoding, CSP, sanitizers, Trusted Types)
- Craft context-appropriate payloads
- Validate execution and demonstrate impact
- Document with reproduction steps and remediation
Reference
reference/xss*.md- XSS bypass techniques and exploitationreference/csrf*.md- CSRF techniques and bypassesreference/cors*.md- CORS misconfiguration testingreference/clickjacking*.md- Clickjacking techniquesreference/dom*.md- DOM-based vulnerability testingreference/prototype-pollution*.md- Prototype pollution techniques
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/transilienceai/communitytools/client-side">View client-side on skillZs</a>