Web & Frontend
Web development agent skills handle frontend and full-stack work: component patterns, CSS and accessibility fixes, performance budgets, and framework conventions. Install a skill once and your AI agent follows the same playbook in every project, from quick prototypes to production apps.
-
outlinedriven-odin-claude-plugin Bundle Tailwind Best PracticesUse when writing, editing, cleaning, or refactoring Tailwind classes, components, or configuration. Not for read-only audits of Tailwind code, or general CSS without Tailwind.
-
outlinedriven-odin-claude-plugin Bundle Web Accessibility AuditUse when the user requests an accessibility audit, a11y check, or WCAG compliance review. Don't use for tasks that require source or remote-system changes.
-
abelrguezr Bundle Text Steganography DetectionDetect and decode hidden data in text using Unicode steganography techniques. Use this skill whenever you need to analyze suspicious text files, CTF challenges with hidden messages, or any text that might contain covert data through homoglyphs, zero-width characters, whitespace patterns, or CSS unicode-range encoding. Trigger this skill for any text forensics, CTF steganography challenges, or when text behaves unexpectedly.
-
outlinedriven-odin-claude-plugin Bundle Visual Argument DiagramUse when a user wants a conceptual, workflow, or architecture diagram, a layout repair, or a PNG render of an existing .excalidraw file. Not for HTML or chat visuals: use visual-diagram or show-me.
-
abelrguezr Bundle Reverse Tab NabbingSecurity skill for identifying and fixing reverse tab nabbing vulnerabilities in HTML links. Use this skill whenever you need to audit HTML code for target="_blank" security issues, review link patterns, or secure web applications against window.opener attacks. This skill helps detect vulnerable anchor tags and provides remediation guidance. Make sure to use this skill when reviewing any HTML with external links, auditing web applications for security vulnerabilities, or when users mention phishing, link security, or target blank issues.
-
abelrguezr Bundle Client Side Path TraversalHow to find and exploit Client Side Path Traversal (CSPT) vulnerabilities in web applications. Use this skill whenever the user mentions path traversal, URL manipulation, OSRF, on-site request forgery, frontend security testing, SPA vulnerabilities, or wants to test for client-side path injection attacks. This skill helps identify when user-controlled input gets concatenated into API paths, fetch requests, or router navigation that can be manipulated to access unauthorized endpoints.
-
abelrguezr Bundle Dom Xss AnalysisAnalyze web applications for DOM-based Cross-Site Scripting (XSS) vulnerabilities. Use this skill whenever the user needs to find, understand, or exploit DOM XSS issues in JavaScript code, HTML pages, or web applications. Trigger on requests about DOM vulnerabilities, JavaScript injection, unsafe sinks, source-to-sink data flow, or any XSS-related security testing.
-
abelrguezr Bundle Vuejs Security AuditSecurity audit and vulnerability assessment for Vue.js applications. Use this skill whenever the user mentions Vue.js security, XSS vulnerabilities, Vue application hardening, frontend security review, or needs to identify security issues in Vue code. Trigger for any Vue.js code review, security assessment, or when users ask about protecting Vue applications from attacks.
-
abelrguezr Bundle Xs Search Connection PoolXS-Search connection pool timing attack for web pentesting. Use this skill whenever you need to exfiltrate data from a target page you cannot directly read, when you can control content that affects page load time, or when you have a CSRF/HTML injection vector and need to extract secrets like flags, tokens, or sensitive data. This technique works when you can make the target load different content based on what you're testing and measure timing differences through connection pool exhaustion. Make sure to use this skill for any XS-Leak, XS-Search, timing-based data exfiltration, or when you have HTML injection without JS execution and need to read protected content.
-
abelrguezr Bundle Angular Security AuditSecurity audit and pentesting guide for Angular applications. Use this skill whenever you need to assess Angular app security, look for XSS vulnerabilities, check for bypassSecurityTrust misuse, audit template injection risks, test for open redirects, or review Angular security configurations. Trigger this for any Angular security review, code audit, or vulnerability assessment of Angular/TypeScript frontend applications.
-
abelrguezr Bundle Shadow Dom XssHow to identify and exploit Cross-Site Scripting (XSS) vulnerabilities in Shadow DOM contexts. Use this skill whenever the user mentions Shadow DOM, web component security, encapsulated DOM attacks, or needs to test for XSS in modern web applications using Shadow DOM. Make sure to use this skill for any pentesting task involving web components, custom elements, or when analyzing applications that use Shadow DOM for encapsulation.
-
abelrguezr Bundle CSS Injection PentestCSS injection attack techniques for web security testing. Use this skill whenever the user mentions CSS injection, style injection, attribute exfiltration, blind CSS attacks, @import exfiltration, unicode-range attacks, font-based data leakage, or any CSS-based information disclosure. Trigger for pentesting tasks involving CSS vulnerabilities, XSS search via CSS, or data exfiltration through style attributes. Make sure to use this skill for any web security assessment where CSS injection vectors are suspected or confirmed.
-
abelrguezr Bundle Dom ClobberingHow to identify and exploit DOM Clobbering vulnerabilities in web applications. Use this skill whenever the user mentions DOM clobbering, ID/name attribute injection, global variable override, document.cookie manipulation, or any XSS technique involving HTML element attributes that can override JavaScript variables. Make sure to use this skill for any web security testing involving DOM-based vulnerabilities, especially when filters might be bypassable through attribute manipulation.
-
abelrguezr Bundle Windows Protocol Handler AbuseWindows Notepad Markdown protocol handler abuse research and defense. Use this skill whenever the user mentions Windows Notepad, Markdown rendering vulnerabilities, ShellExecuteExW, protocol handler abuse, CVE-2026-20841, or needs to create PoC payloads, detection rules, or understand the attack surface of Windows applications that render Markdown/HTML with weak scheme allowlisting.
-
abelrguezr Bundle CSS Injection ExfiltrationHow to perform CSS injection attacks to exfiltrate data from input fields using CSS selectors and @import. Use this skill whenever the user mentions CSS injection, style injection, data exfiltration from forms, input field attacks, or wants to extract secrets from HTML input values. This is essential for web security testing when you need to extract hidden or sensitive data from input fields that can't be accessed through normal means.
-
abelrguezr Bundle Less Code InjectionExploit LESS code injection vulnerabilities to perform SSRF and local file read attacks. Use this skill whenever you need to test for CSS preprocessor injection, identify vulnerable endpoints that process user input through LESS compilers, or extract sensitive files and cloud metadata via @import (inline) directives. Trigger this skill for any web application security testing involving CSS generation, stylesheet preview endpoints, or when you suspect user-controlled input reaches a LESS processor.
-
abelrguezr Bundle Lazy Image SidechannelHow to perform timing-based side-channel attacks using lazy image loading and event loop blocking. Use this skill whenever the user mentions timing attacks, side-channel exploits, lazy loading vulnerabilities, image loading timing, event loop blocking, or wants to leak data through timing differences in web applications. This is especially useful for CTF challenges involving HTML injection with timing oracles, or when you need to extract hidden data through performance-based side channels.
-
abelrguezr Bundle Sitecore Xp PentestSecurity testing skill for Sitecore Experience Platform (XP) vulnerabilities including pre-auth HTML cache poisoning and post-auth RCE via BinaryFormatter deserialization. Use this skill whenever the user mentions Sitecore XP, Sitecore security testing, cache poisoning, XAML handler exploitation, or deserialization attacks against Sitecore. Trigger for any Sitecore vulnerability assessment, penetration testing, or security review tasks.
-
abelrguezr Bundle React Native PentestPentest React Native Android applications. Use this skill whenever analyzing React Native apps, extracting and analyzing index.android.bundle files, hunting for secrets in JS bundles, handling Hermes bytecode, or performing dynamic analysis with Frida. Trigger for any React Native security assessment, bundle analysis, secret extraction, or mobile app testing involving React Native frameworks.
-
abelrguezr Bundle Ss Leaks DetectionDetect and analyze Server-Side Leaks (SS-Leaks) vulnerabilities in web applications. Use this skill whenever the user mentions server-side leaks, information disclosure, error message analysis, stack trace exposure, or wants to audit web applications for sensitive data leakage. This skill helps identify when server-side information is being improperly exposed to clients through error messages, debug output, or other response channels.
-
abelrguezr Bundle Dangling Markup HTML InjectionHow to exploit HTML injection vulnerabilities using dangling markup techniques to exfiltrate data, steal forms, bypass CSP, and manipulate page behavior without JavaScript execution. Use this skill whenever the user mentions HTML injection, scriptless attacks, XSS bypass, CSP bypass, data exfiltration, form stealing, or any scenario where they can inject HTML tags but not JavaScript. Also trigger for dangling markup, HTML namespace attacks, form action manipulation, or when testing for HTML injection vulnerabilities.
-
abelrguezr Bundle Macos Tcc AnalyzerAnalyze macOS TCC (Transparency, Consent, and Control) permissions, query TCC databases, and assess TCC-based privilege escalation opportunities. Use this skill whenever the user mentions macOS security, TCC permissions, privacy protections, Full Disk Access, accessibility permissions, automation permissions, or any macOS application permission auditing. Trigger for security assessments, penetration testing, or understanding what permissions apps have on macOS systems.
-
abelrguezr Bundle Ashen Lepus Dll Sideloading AnalysisAnalyze and detect Ashen Lepus (WIRTE) advanced DLL side-loading attacks with HTML-staged payloads. Use this skill whenever investigating suspicious DLL loading patterns, HTML-based C2 staging, or Middle Eastern diplomatic targeting campaigns. Trigger for any analysis of netutils.dll, srvcli.dll, dwampi.dll, wtsapi32.dll, or propsys.dll side-loading, HTML comment-based payload extraction, or Rclone-based exfiltration patterns.
-
abelrguezr Bundle Macos Tcc PayloadsmacOS TCC (Transparency, Consent, and Control) security testing payloads. Use this skill when testing macOS security controls, auditing TCC permissions, or researching macOS privacy protections. Covers Desktop, Documents, Downloads, Photos, Contacts, Calendar, Camera, Microphone, Location, Screen Recording, and Accessibility TCC services with Objective-C and shell payloads. Make sure to use this skill whenever the user mentions macOS security testing, TCC bypass, privacy permission auditing, or needs to test access to protected macOS resources.
-
betterpromptme Skill Exploded ViewThis prompt instructs an AI to act as a technical illustrator and produce a photorealistic, high-resolution exploded view diagram of a specified object, using provided color accents and a component list. The result is a proportionally accurate, correctly oriented visualization in which every relevant internal and external part (including small fasteners and connectors) is separated but precisely aligned to show assembly relationships, organized with clear labeling or hierarchy on a neutral studio background, while avoiding invented components, branding, and clutter.
-
betterpromptme Skill Focus DescribeThis prompt instructs the AI to examine an input image and generate a concise, vivid, and neutral accessibility-focused description of a user-specified subject, covering visible elements such as colors, composition, objects, actions, and overall mood while avoiding opinions, copyrighted content creation, and unsupported inferences; if details are unclear, it explicitly requires the AI to note uncertainty.
-
betterpromptme Skill Retro Adventure Diner SelfieThis prompt instructs an AI image generator to produce an ultra-realistic, analog-film 1980s-style fisheye group selfie set in a classic 1960s American diner, placing the user (with facial features matched exactly to a provided reference photo) among six wholly original, fictional 80s teen/young-adult characters who all react with surprised expressions. It specifies detailed environment props, lighting, lens/film characteristics, composition, mood, and allowed on-scene text, while also enforcing strict constraints against altering the user’s face, adding extra people, using non-photoreal styles for the user, or resembling any real or copyrighted characters, resulting in a cohesive cinematic retro “adventure team” portrait.
-
betterpromptme Skill Your Imagination Now A KeychainThis prompt instructs the AI to turn the person in the provided photo into a cute 3D cartoon keychain character, simplifying facial features and pose into a smooth, toy-like figure with a silicone-style texture and pastel colors. It specifies adding a keychain component and an attached name tag displaying “{{ Name }}” in a playful rounded font, while keeping the output as a clean product-style render with no background and minimal shadows.
-
bbgnsurftech Skill Code FormatterAutomatically formats and validates code files using Prettier and other formatting tools. Use when users mention "format my code", "fix formatting", "apply code style", "check formatting", "make code consistent", or "clean up code formatting". Handles JavaScript, TypeScript, JSON, CSS, Markdown, and many other file types.
-
bbgnsurftech Skill Adk Agent BuilderBuild production-ready AI agents using Google's Agent Development Kit with Claude integration, React patterns, multi-agent orchestration, and comprehensive tool libraries
-
bbgnsurftech Bundle Running E2e TestsExecute end-to-end tests covering full user workflows across frontend and backend. Use when performing specialized testing. Trigger with phrases like "run end-to-end tests", "test user flows", or "execute E2E suite".
-
bbgnsurftech Bundle Managing Snapshot TestsCreate and validate component snapshots for UI regression testing. Use when performing specialized testing. Trigger with phrases like "update snapshots", "test UI snapshots", or "validate component snapshots".
-
bbgnsurftech Bundle Tracking Application Response TimesTrack and optimize application response times across API endpoints, database queries, and service calls. Use when monitoring performance or identifying bottlenecks. Trigger with phrases like "track response times", "monitor API performance", or "analyze latency".
-
bbgnsurftech Bundle Running Integration TestsExecute integration tests validating component interactions and system integration. Use when performing specialized testing. Trigger with phrases like "run integration tests", "test integration", or "validate component interactions".
-
bbgnsurftech Bundle Scanning For Xss VulnerabilitiesThis skill enables claude to automatically scan for xss (cross-site scripting) vulnerabilities in code. it is triggered when the user requests to "scan for xss vulnerabilities", "check for xss", or uses the command "/xss". the skill identifies ref...
-
bbgnsurftech Bundle Scanning AccessibilityValidate WCAG compliance and accessibility standards (ARIA, keyboard navigation). Use when auditing WCAG compliance or screen reader compatibility. Trigger with phrases like "scan accessibility", "check WCAG compliance", or "validate screen readers".
Frequently asked questions
What are Web & Frontend agent skills?
Web development agent skills handle frontend and full-stack work: component patterns, CSS and accessibility fixes, performance budgets, and framework conventions. Install a skill once and your AI agent follows the same playbook in every project, from quick prototypes to production apps.
Which Web & Frontend skills are most installed?
Popular Web & Frontend skills on SkillMD right now include text-steganography-detection, reverse-tab-nabbing, client-side-path-traversal. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Web & Frontend skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.