xss-cross-site-scripting
What this skill does
Security/Teaching Skill
github/yaklang - Security Teaching - 1.6k stars
Threat analysis
Skill info
pkg:github/yaklang/hack-skills@c9a4b9e?skill=xss-cross-site-scriptingAssessments (2)
Security Teaching
Security Teaching via local-llm-review
SKILL.md
Skill explicitly teaches XSS techniques, WAF/CSP bypass, and post-exploitation strategies. This is a security/teaching skill, not an actual exploit.Security Teaching via local-llm-review
ADVANCED_XSS_TRICKS.md
Document contains detailed XSS bypass techniques (e.g., mXSS, DOM clobbering, DOMPurify bypasses). This is teaching material, not an actual exploit.Badge
Add the Anomity scan badge for xss-cross-site-scripting to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of xss-cross-site-scripting? Report an issue or request a rescan.




