HTML Injection Testing

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This document is a highly actionable HTML injection testing guide that doubles as an offensive playbook for phishing, credential harvesting, and site defacement. While it contains accurate remediation guidance suitable for defenders, the inclusion of ready-to-use payloads, explicit attacker endpoints, automated testing scripts, and evasion techniques elevates its misuse risk. Treat distribution as sensitive: require authorization for use, replace external endpoints with safe placeholders in demonstrations, and emphasize legal/scope constraints. Remediation advice should be followed by developers to close the described sinks (context-aware encoding, CSP, sanitizers like DOMPurify, input validation, and safe use of innerHTML).

Confidence: 75%Severity: 85%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:15 PM
Package URL
pkg:socket/skills-sh/automindtechnologie-jpg%2Fultimate-skill.md%2Fhtml-injection-testing%2F@fd8248e61bfaf7d301cdf171e91d80483644b2bd