Back to Skills

scanning-for-xss-vulnerabilities

verified
View on GitHub

Marketplace

claude-code-plugins-plus

jeremylongshore/claude-code-plugins-plus-skills

Plugin

xss-vulnerability-scanner

security

Repository

jeremylongshore/claude-code-plugins-plus-skills
1.1kstars

plugins/security/xss-vulnerability-scanner/skills/scanning-for-xss-vulnerabilities/SKILL.md

Last Verified

January 22, 2026

Install Skill

Select agents to install to:

Scope:
npx add-skill https://github.com/jeremylongshore/claude-code-plugins-plus-skills/blob/main/plugins/security/xss-vulnerability-scanner/skills/scanning-for-xss-vulnerabilities/SKILL.md -a claude-code --skill scanning-for-xss-vulnerabilities

Installation paths:

Claude
.claude/skills/scanning-for-xss-vulnerabilities/
Powered by add-skill CLI

Instructions

# Xss Vulnerability Scanner

This skill provides automated assistance for xss vulnerability scanner tasks.

## Overview

This skill empowers Claude to proactively identify and report XSS vulnerabilities within your codebase. By leveraging advanced detection techniques, including context-aware analysis and WAF bypass testing, this skill ensures your web applications are resilient against common XSS attack vectors. It provides detailed insights into vulnerability types and offers guidance on remediation strategies.

## How It Works

1. **Activation**: Claude recognizes the user's intent to scan for XSS vulnerabilities through specific trigger phrases like "scan for XSS" or the shortcut "/xss".
2. **Code Analysis**: The plugin analyzes the codebase, identifying potential XSS vulnerabilities across different contexts (HTML, JavaScript, CSS, URL).
3. **Vulnerability Detection**: The plugin detects reflected, stored, and DOM-based XSS vulnerabilities by injecting various payloads and analyzing the responses.
4. **Reporting**: The plugin generates a report highlighting identified vulnerabilities, their location in the code, and recommended remediation steps.

## When to Use This Skill

This skill activates when you need to:
- Perform a security audit of your web application.
- Review code for potential XSS vulnerabilities.
- Ensure compliance with security standards.
- Test the effectiveness of your Content Security Policy (CSP).
- Identify and mitigate XSS vulnerabilities before deploying to production.

## Examples

### Example 1: Detecting Reflected XSS

User request: "scan for XSS vulnerabilities in the search functionality"

The skill will:
1. Analyze the code related to the search functionality.
2. Identify a reflected XSS vulnerability in how search queries are displayed.
3. Report the vulnerability, including the affected code snippet and a suggested fix using proper sanitization.

### Example 2: Identifying Stored XSS

User request: "/xss check the comment submiss

Validation Details

Front Matter
Required Fields
Valid Name Format
Valid Description
Has Sections
Allowed Tools
Instruction Length:
3636 chars