Sec Scan XSS — AI skill for Claude Code
XSS 취약점 진단 — Persistent / Reflected / DOM / Redirect XSS — scan_xss.py + LLM 교차검증.
How to install Sec Scan XSS
Installs to ~/.claude/commands/hssg1109-palantir-sec-scan-xss.md
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/hssg1109/palantir/HEAD/.claude/commands/sec-scan-xss.md -o ~/.claude/commands/hssg1109-palantir-sec-scan-xss.md Restart Claude Code, or start a new session, for it to be picked up.
What Sec Scan XSS does
allowed-tools: Read, Glob, Grep, Bash, Edit, Write, Agent, WebFetch description: XSS 취약점 진단 — Persistent / Reflected / DOM / Redirect XSS — scan_xss.py + LLM 교차검증
Sec Scan XSS
대상: $ARGUMENTS (미입력 시 testbed/ 내 대상 목록을 먼저 확인)
실행 절차
`sec-scan-xss/SKILL.md` 전체 내용을 읽고 절차대로 실행할 것.
sec-scan-xss/SKILL.md읽기shared/references/task_prompts/task_11_asset_identification.md읽기sec-scan-xss/references/task_prompts/task_23_xss_review.md읽기- 공유 references (
shared/references/)
Alternatives in AI
- Osaurus — Own your AI. The native macOS harness for AI agents -- any model, persistent memory, autonomous execution, cry 5.1k ★
- Agentmemory — #1 Persistent memory for AI coding agents based on real-world benchmarks 1.9k ★
- Graymatter — 30 sec to give your AI agents persistent memory 460 ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Sec Scan File
파일 처리 취약점 진단 — File Upload / Download / LFI / RFI — scan_file_processing.py + LLM 교차검증
Sec Scan Auth
인증/인가/어뷰징 취약점 진단 — Auth Bypass / IDOR / Mass Assignment / Rate Limit / 멱등성 / 클라이언트 신뢰 로직 — scan_api.py + scan_
Svelte Markdown
📝 Markdown and HTML renderer for Svelte 5 — built for streaming AI agent output from Claude Code, ChatGPT, an
Sdlc Steering
Bootstrap or sync project-wide steering files (.sdlc/steering/) by analyzing the codebase. Use after code exis
Bead Sweep
Scan open beads for stale trackers already implemented — deterministic checks then LLM verification.
Tauri Plugin MCP
Allows AI agents (e.g., Cursor, Claude Code) to debug within Tauri apps via screenshot capture, window managem
Related Agents
XSS Hunter
Active XSS hunter for an ingested program. Consumes webvuln-surface injection points (reflected params + DOM s
Cacador Injecao
Caçador do domínio de injeção na auditoria NIST — SQL, NoSQL, comando de SO, path traversal, SSTI, XSS refleti
Trisakion Security Audit Agent
보안 취약점(trisakion-dev-convention-skill 14장) — S2S HMAC 인증(14.1), SQL Injection(14.2), 비밀번호 저장(14.3), XSS/CSRF/h