Dangling Markup Injection skill: what it does and how to install it
Exfiltrates page content through HTML injection when JavaScript is blocked, using dangling tags, form actions and other browser requests.
Summary generated from the skill's documentation.
Warning. A security audit flagged this skill with a warning. Read its SKILL.md and scripts before you install it.
Install
$ npx skills add yaklang/hack-skills --skill dangling-markup-injectionRun it in a terminal. If your agent is already running, start a new session so it picks the skill up.
About this skill
What it does. Provides a browser-focused playbook for turning reflected or stored HTML injection into data exfiltration without JavaScript. It selects unclosed image, form, base, link or media tags according to the injection context, CSP and browser, and covers captured tokens, page content, quote matching and attack combinations.
When to use it. Use it when HTML injection remains possible but scripts are blocked and sensitive content appears later in the response. It is not useful when no target data follows the injection, or when full XSS is available and dangling markup is unnecessary.
History
Repo stars
2.4k
Tracking since . A chart appears once there are 7 days of data.
Stars are counted for the whole repository, which holds 10 skills.
Installs
3.3k
Tracking since . A chart appears once there are 7 days of data.
Installs via skills.sh
Similar skills
- Browser Testing with DevToolsTests web apps in a real browser through Chrome DevTools MCP: inspect the DOM, read console errors, analyse network requests and profile performance.
- Requesting Code ReviewRequests a code review to verify that completed work meets its requirements before merging.
- Using Git WorktreesSets up an isolated workspace with git worktrees before feature work or plan execution begins.