client-side

v2026.09.24

Client-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution.

GitHub
Install command
npx skhub add transilienceai/client-side
Markdown
SKILL.md

Client-Side

Test for client-side vulnerabilities across modern web applications and SPAs.

Techniques

TypeKey Vectors
XSSReflected, Stored, DOM-based, framework-specific (React, Vue, Angular)
CSRFToken bypass, SameSite cookie bypass, cross-origin requests
CORSMisconfigured origins, null origin, wildcard credentials
ClickjackingFrame-based, drag-and-drop, multi-step
DOM-basedDOM sinks, source/sink analysis, JavaScript URL schemes
Prototype PollutionClient-side gadgets, server-side pollution, property injection

Workflow

  1. Identify input sources and data flows
  2. Classify sink contexts (HTML, attribute, URL, JS, CSS)
  3. Enumerate defenses (encoding, CSP, sanitizers, Trusted Types)
  4. Craft context-appropriate payloads
  5. Validate execution and demonstrate impact
  6. Document with reproduction steps and remediation

Reference

  • reference/xss*.md - XSS bypass techniques and exploitation
  • reference/csrf*.md - CSRF techniques and bypasses
  • reference/cors*.md - CORS misconfiguration testing
  • reference/clickjacking*.md - Clickjacking techniques
  • reference/dom*.md - DOM-based vulnerability testing
  • reference/prototype-pollution*.md - Prototype pollution techniques
Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

skills/client-side

Default branch

main

Latest commit

95fdc12

Tree SHA

854bd03