performing-content-security-policy-bypass

mukul975/performing-content-security-policy-bypass · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations, JSONP endpoints, unsafe directives, and policy injection techniques.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 6.5 KB
  • 📁scripts
  • ⚙️agent.py 11.0 KB
  • 📄LICENSE 11.0 KB

Related

  1. testing-for-xss-vulnerabilities-with-burpsuite · mukul975 bundle
    Identify and validate cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.
    24.6k
    repo stars
  2. cross-site-scripting-xss-complete-deep-dive · shulkwisec bundle
    Provides a complete deep-dive into Cross-Site Scripting (XSS) with exact payloads and bypass techniques for every PortSwigger lab variant, from apprentice to expert level.
    21
    repo stars
  3. testing-for-xss-vulnerabilities · mukul975 bundle
    Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and user impersonation.
    24.6k
    repo stars
  4. csrf · shulkwisec
    Detect and exploit Cross-Site Request Forgery vulnerabilities by testing for missing or predictable CSRF tokens, absent SameSite cookie attributes, and JSON endpoints accepting text/plain Content-Type, with payloads and bypass techniques for security testing.
    21
    repo stars
  5. cors-misconfiguration-complete-deep-dive · shulkwisec bundle
    Provides a structured deep-dive into CORS misconfiguration vulnerabilities with exact payloads for every PortSwigger lab variant, including zero-day escalation techniques and blue-team detection guidance.
    21
    repo stars
  6. dom-xss · shulkwisec
    Detect and exploit DOM-based XSS vulnerabilities by auditing JavaScript for tainted data flow from controllable sources to dangerous sinks, with payloads and bypass techniques for client-side testing.
    21
    repo stars

Frequently asked questions

How do I install the performing-content-security-policy-bypass skill?

Run npx skillmds add mukul975/performing-content-security-policy-bypass in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the performing-content-security-policy-bypass skill do?

Analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations, JSONP endpoints, unsafe directives, and policy injection techniques. It is listed under Security, Penetration Testing on SkillMD.

Is performing-content-security-policy-bypass safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: FAIL. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with performing-content-security-policy-bypass?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is performing-content-security-policy-bypass free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published performing-content-security-policy-bypass?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.