html-injection-testing

Warn

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill provides functional HTML and CSS templates designed to exfiltrate sensitive data, such as user credentials through fake login forms and session cookies via style-based tracking payloads, directed to external domains (e.g., attacker.com).
  • [COMMAND_EXECUTION]: Includes an automated Python fuzzing script using the 'requests' library and various 'curl' command examples designed to deliver malicious payloads to target web applications.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 29, 2026, 05:55 PM