Exploit XSS — Research agent for Claude Code
XSS exploitation with session hijacking.
How to install Exploit XSS
Installs to ~/.claude/agents/us-shannon-on-claude-code-exploit-xss.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/us/shannon-on-claude-code/HEAD/.claude/agents/exploit-xss.md -o ~/.claude/agents/us-shannon-on-claude-code-exploit-xss.md Restart Claude Code, or start a new session, for it to be picked up.
What Exploit XSS does
name: exploit-xss description: XSS exploitation with session hijacking. Requires XSS analysis deliverable. tools: Read, Grep, Glob, Write, Edit, Bash, Agent, mcp__playwright__*, mcp__shannon-tools__* model: claude-sonnet-4-6 maxTurns: 500
IMPORTANT: In your instructions below, wherever you see "TARGET_URL_PLACEHOLDER", use the actual target URL provided to you when this agent was launched. Wherever you see "REPO_PATH_PLACEHOLDER", your working directory IS the repo. Wherever you see "LO
Alternatives in Research
- Hooks: — You are a GSD codebase mapper 38.5k ★
- Attack Tree Construction — Systematic attack path visualization and analysis 31.9k ★
- Skill — Professional finance research toolkit — backtesting (10 engines + benchmark comparison panel), factor analysis 31.7k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Exploit Auth
Authentication exploitation and account takeover. Requires auth analysis deliverable.
Exploit Authz
Authorization exploitation and privilege escalation. Requires authz analysis deliverable.
Exploit Researcher
Vulnerability research agent — identifies CVEs, finds exploit PoCs, maps attack chains, and develops custom ex
Deal Factchecker
Verifies every factual, legal, and market claim in a contract analysis against primary sources, and stamps wha
Redteam Report Writer
Final report writer for red-team workflows. Use this agent at the end of CMS, recon, source analysis, exploit,
Bundle Isolation Tester
Use this agent for adversarial analysis of cross-tenant isolation in workerd-style hypervisors — slice-grant e
Related Skills
Engage.Exploit
Execute Phase 4 - Exploitation and Access Establishment
Chain
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common ch
Pentest
Run an AI-powered penetration test against a target URL + source code repo. Usage: /pentest [--config ] --ski