jeremylongshore/claude-code-plugins-plus-skills
xss-vulnerability-scanner
plugins/security/xss-vulnerability-scanner/skills/scanning-for-xss-vulnerabilities/SKILL.md
January 22, 2026
Select agents to install to:
npx add-skill https://github.com/jeremylongshore/claude-code-plugins-plus-skills/blob/main/plugins/security/xss-vulnerability-scanner/skills/scanning-for-xss-vulnerabilities/SKILL.md -a claude-code --skill scanning-for-xss-vulnerabilitiesInstallation paths:
.claude/skills/scanning-for-xss-vulnerabilities/# Xss Vulnerability Scanner This skill provides automated assistance for xss vulnerability scanner tasks. ## Overview This skill empowers Claude to proactively identify and report XSS vulnerabilities within your codebase. By leveraging advanced detection techniques, including context-aware analysis and WAF bypass testing, this skill ensures your web applications are resilient against common XSS attack vectors. It provides detailed insights into vulnerability types and offers guidance on remediation strategies. ## How It Works 1. **Activation**: Claude recognizes the user's intent to scan for XSS vulnerabilities through specific trigger phrases like "scan for XSS" or the shortcut "/xss". 2. **Code Analysis**: The plugin analyzes the codebase, identifying potential XSS vulnerabilities across different contexts (HTML, JavaScript, CSS, URL). 3. **Vulnerability Detection**: The plugin detects reflected, stored, and DOM-based XSS vulnerabilities by injecting various payloads and analyzing the responses. 4. **Reporting**: The plugin generates a report highlighting identified vulnerabilities, their location in the code, and recommended remediation steps. ## When to Use This Skill This skill activates when you need to: - Perform a security audit of your web application. - Review code for potential XSS vulnerabilities. - Ensure compliance with security standards. - Test the effectiveness of your Content Security Policy (CSP). - Identify and mitigate XSS vulnerabilities before deploying to production. ## Examples ### Example 1: Detecting Reflected XSS User request: "scan for XSS vulnerabilities in the search functionality" The skill will: 1. Analyze the code related to the search functionality. 2. Identify a reflected XSS vulnerability in how search queries are displayed. 3. Report the vulnerability, including the affected code snippet and a suggested fix using proper sanitization. ### Example 2: Identifying Stored XSS User request: "/xss check the comment submiss