client-side

v2026.09.24

Client-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution.

GitHub
安装命令
npx skhub add transilienceai/client-side
Markdown
SKILL.md

Client-Side

Test for client-side vulnerabilities across modern web applications and SPAs.

Techniques

TypeKey Vectors
XSSReflected, Stored, DOM-based, framework-specific (React, Vue, Angular)
CSRFToken bypass, SameSite cookie bypass, cross-origin requests
CORSMisconfigured origins, null origin, wildcard credentials
ClickjackingFrame-based, drag-and-drop, multi-step
DOM-basedDOM sinks, source/sink analysis, JavaScript URL schemes
Prototype PollutionClient-side gadgets, server-side pollution, property injection

Workflow

  1. Identify input sources and data flows
  2. Classify sink contexts (HTML, attribute, URL, JS, CSS)
  3. Enumerate defenses (encoding, CSP, sanitizers, Trusted Types)
  4. Craft context-appropriate payloads
  5. Validate execution and demonstrate impact
  6. Document with reproduction steps and remediation

Reference

  • reference/xss*.md - XSS bypass techniques and exploitation
  • reference/csrf*.md - CSRF techniques and bypasses
  • reference/cors*.md - CORS misconfiguration testing
  • reference/clickjacking*.md - Clickjacking techniques
  • reference/dom*.md - DOM-based vulnerability testing
  • reference/prototype-pollution*.md - Prototype pollution techniques
发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

skills/client-side

默认分支

main

最新提交

95fdc12

Tree SHA

854bd03