Agent skill · Security

Advanced Reflected XSS Payload Crafting Methodology

A systematic, first-principles approach to crafting advanced Cross-Site Scripting (XSS) payloads by analyzing reflection contexts, identifying constraints, and applying obfuscation techniques to bypass filters.

ECNU-ICALKgithub.com/ECNU-ICALKGitHub ↗
claude-code
Install
npx skills add ECNU-ICALK/AutoSkill --skill advanced-reflected-xss-payload-crafting-methodology --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 1
SKILL.md size: 4 KB
Bundled scripts: none
Version: 0.1.0
Path: SkillBank/ConvSkill/english_gpt4_8/advanced-reflected-xss-payload-crafting-methodology/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 539
Language: Python

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

From the SKILL.md

# Advanced Reflected XSS Payload Crafting Methodology A systematic, first-principles approach to crafting advanced Cross-Site Scripting (XSS) payloads by analyzing reflection contexts, identifying constraints, and applying obfuscation techniques to bypass filters. ## Prompt # Role & Objective You are an expert Web Security Specialist and Bug Bounty Hunter. Your objective is to teach the user how to craft advanced Reflected XSS payloads for any given context using a step-by-step, first-principles methodology. You must explain the theory behind the payload construction, not just provide the syntax. # Communication & Style Preferences - Use clear, technical language suitable for security researchers. - Break down complex concepts into fundamental principles (e.g., how browsers parse HTML/JS). - Provide concrete examples for different contexts (HTML Body, HTML Attribute, JavaScript String). - Always explain the 'why' behind a technique (e.g., why we use a specific constructor or encoding). # Operational Rules & Constraints 1. **Context Analysis**: Always start by identifying exactly where and how the user input is reflected (e.g., inside a JavaScript variable, within an HTML attribute

What's inside
Steps it walks through
  1. Prompt
  2. Triggers
More from AutoSkill
All skills →
About this skill
What does the Advanced Reflected XSS Payload Crafting Methodology skill do?

A systematic, first-principles approach to crafting advanced Cross-Site Scripting (XSS) payloads by analyzing reflection contexts, identifying constraints, and applying obfuscation techniques to bypass filters.

How do I install it?

Run `npx skills add ECNU-ICALK/AutoSkill --skill advanced-reflected-xss-payload-crafting-methodology --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From ECNU-ICALK/AutoSkill, a repository with 539 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going