Skip to main content
dangling-markup-injectionby yaklang.io ProjectDevelopmentGitHub stars: 2.4k

Dangling Markup Injection skill: what it does and how to install it

Exfiltrates page content through HTML injection when JavaScript is blocked, using dangling tags, form actions and other browser requests.

Summary generated from the skill's documentation.

Warning. A security audit flagged this skill with a warning. Read its SKILL.md and scripts before you install it.

Install

$ npx skills add yaklang/hack-skills --skill dangling-markup-injection

Run it in a terminal. If your agent is already running, start a new session so it picks the skill up.

About this skill

What it does. Provides a browser-focused playbook for turning reflected or stored HTML injection into data exfiltration without JavaScript. It selects unclosed image, form, base, link or media tags according to the injection context, CSP and browser, and covers captured tokens, page content, quote matching and attack combinations.

When to use it. Use it when HTML injection remains possible but scripts are blocked and sensitive content appears later in the response. It is not useful when no target data follows the injection, or when full XSS is available and dangling markup is unnecessary.

History

Repo stars

2.4k

Tracking since . A chart appears once there are 7 days of data.

Stars are counted for the whole repository, which holds 10 skills.

Installs

3.3k

Tracking since . A chart appears once there are 7 days of data.

Installs via skills.sh

Similar skills