html-injection-testing
Warn
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill provides functional HTML and CSS templates designed to exfiltrate sensitive data, such as user credentials through fake login forms and session cookies via style-based tracking payloads, directed to external domains (e.g., attacker.com).
- [COMMAND_EXECUTION]: Includes an automated Python fuzzing script using the 'requests' library and various 'curl' command examples designed to deliver malicious payloads to target web applications.
Audit Metadata