bookforge-xss-detection-and-exploitationDetect, exploit, and remediate cross-site scripting (XSS) vulnerabilities across all three varieties — reflected, stored, and DOM-based — in web applications...
Install via ClawdBot CLI:
clawdbot install quochungto/bookforge-xss-detection-and-exploitationGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
http://app.com/page#<scriptAudited May 1, 2026 · audit v1.0
Generated May 12, 2026
An e-commerce platform with a reflected XSS vulnerability in the search field allows attackers to craft a malicious URL that, when clicked by an admin, exfiltrates the admin's session cookie and enables account takeover or manipulation of pricing.
A social media site has a stored XSS flaw in user profile bios. An attacker injects a self-propagating script that automatically adds the attacker as a friend and posts the same script to the victim's profile, potentially infecting millions of users.
A banking application uses client-side JavaScript that reads from window.location.hash and writes to innerHTML without sanitization. Attackers can craft a URL with a malicious hash to steal session tokens or perform actions on behalf of the user.
A healthcare patient portal reflects user input in error messages without encoding. An attacker phishes a patient with a link containing a script that exfiltrates medical records or appointment details, violating HIPAA privacy.
A SaaS business tool with a stored XSS in user display names allows an attacker to inject JavaScript that steals API keys from other users' dashboard interactions, leading to data breaches and service compromise.
Offer specialized XSS detection and exploitation as a service to enterprises needing security assessments. Revenue comes from per-engagement or retainer fees.
Independent security researchers use this skill to find XSS vulnerabilities on bug bounty platforms like HackerOne or Bugcrowd. Revenue is earned per validated report, with payouts varying by severity and program.
Develop and deliver training courses on XSS detection and exploitation for corporate development teams or security bootcamps. Revenue comes from course fees or consulting hours.
💬 Integration Tip
Combine with automated scanning tools like Burp Suite or OWASP ZAP to quickly identify injection points, then use manual payload crafting and browser dev tools for filter bypass and validation.
Scored May 12, 2026
Meta-skill for AI agent self-improvement. Analyzes runtime logs to detect error patterns, regressions, and inefficiencies, then generates structured improvem...
Stop waiting for prompts. Keep working.
Turn OpenClaw into a learning-loop agent with seeded workspace rules, skill promotion, reflective memory, and proactive maintenance.
Meta-agent skill for orchestrating complex tasks through autonomous sub-agents. Decomposes macro tasks into subtasks, spawns specialized sub-agents with dynamically generated SKILL.md files, coordinates file-based communication, consolidates results, and dissolves agents upon completion. MANDATORY TRIGGERS: orchestrate, multi-agent, decompose task, spawn agents, sub-agents, parallel agents, agent coordination, task breakdown, meta-agent, agent factory, delegate tasks
Guide for creating effective skills. This skill should be used when users want to create a new skill (or update an existing skill) that extends Claude's capabilities with specialized knowledge, workflows, or tool integrations.
Complete toolkit for creating autonomous AI agents and managing Discord channels for OpenClaw. Use when setting up multi-agent systems, creating new agents, or managing Discord channel organization.