mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-08-03 09:20:18 +03:00
Rewrite 548 skill descriptions to the activation rubric
Each rewritten description now states both what the skill does (concrete capability, named tools/artifacts) and an explicit when-to-use trigger, improving agent discovery/activation. Grounded in each skill's own body; changes confined to the `description` field only (bodies and all other frontmatter untouched). Produced by a gated audit->rewrite->recheck loop (548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded). Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
@@ -1,14 +1,10 @@
|
||||
---
|
||||
name: testing-for-xss-vulnerabilities
|
||||
description: 'Tests web applications for Cross-Site Scripting (XSS) vulnerabilities
|
||||
by injecting JavaScript payloads into reflected, stored, and DOM-based contexts
|
||||
to demonstrate client-side code execution, session hijacking, and user impersonation.
|
||||
The tester identifies all injection points and output contexts, crafts context-appropriate
|
||||
payloads, and bypasses sanitization and CSP protections. Activates for requests
|
||||
involving XSS testing, cross-site scripting assessment, client-side injection testing,
|
||||
or JavaScript injection vulnerability testing.
|
||||
|
||||
'
|
||||
description: Tests web applications for reflected, stored, and DOM-based Cross-Site
|
||||
Scripting by injecting JavaScript payloads with Burp Suite (XSS extensions, Active
|
||||
Scan++) and browser tools, then bypassing sanitization and CSP to demonstrate session
|
||||
hijacking and user impersonation. Use for OWASP WSTG client-side injection testing or
|
||||
when evaluating input sanitization and output encoding coverage.
|
||||
domain: cybersecurity
|
||||
subdomain: penetration-testing
|
||||
tags:
|
||||
|
||||
Reference in New Issue
Block a user