Skip to main content

xssi-and-client-framework

XSSI (cross-site script inclusion) and client-side framework attack techniques -- JSONP hijacking, AngularJS sandbox escapes, Vue/React unsafe-HTML sinks, client-side prototype pollution gadgets, service-worker hijacking, Sass/SCSS server-side injection, and full DOM clobbering. Converted from master-pentest-prompt.md Phase 25. Use on any endpoint returning JS/JSONP containing authenticated data, and on any modern JS-framework-heavy frontend.

跳到安装

来源信息

仓库
ankitsingh015/HuntMCP
最近来源活动
2026年8月24日 12:34
检测到的 SKILL.md 语言
英语
星标
4
分支
0

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。