dangling-markup-injection
Addresses HTML injection when CSP, sanitizers, or WAF rules prevent JavaScript execution. Describes unclosed HTML tags that capture subsequent page content and expose CSRF tokens, session data, or other page information.
Your agent can do more. Find the skill that makes it happen.
Find your next superpower If you are an agent, refer to our llms.txt for full access.Addresses HTML injection when CSP, sanitizers, or WAF rules prevent JavaScript execution. Describes unclosed HTML tags that capture subsequent page content and expose CSRF tokens, session data, or other page information.
Supports creating and maintaining documentation sites with Mintlify. Covers documentation pages, navigation configuration, components, and API reference setup.
Provides a network protocol attack playbook covering ARP spoofing, name-resolution poisoning, WPAD abuse, DHCPv6 attacks, VLAN hopping, and STP manipulation. Also includes DNS spoofing, IPv6 attacks, and IDS/IPS evasion.
Supports writing, reviewing, and editing files in a repository's /docs directory. Also covers Markdown files elsewhere in the repository.
Builds a complete palette from a single brand hex colour, including an 11-shade scale, semantic tokens, and dark mode variants. Produces Tailwind v4 CSS and checks WCAG colour contrast.
Uses more than 20 creative methodologies, including SIT, TRIZ, SCAMPER, and Synectics. Combines recursive self-assessment, three-axis evaluation informed by Cannes, D&AD, and HumanKind, and a five-phase process from brief to presentation.
Applies suitable VueUse composables when developing Vue.js or Nuxt features, with an emphasis on concise and maintainable code.
Covers XSLT processor fingerprinting, XXE, document() SSRF, and EXSLT write primitives. Examines PHP, Java, and .NET extension code execution surfaces where users control stylesheets or transform inputs.
Integrates with Feishu/Lark through MCP. Supports messaging, group creation, Bitable operations, document import and search, and knowledge base queries.
Author and review WordPress Playground Blueprints, including schema keys, steps, and resources. Supports debugging Blueprint files and assembling Blueprint bundles.
Creates metrics for experiments or rollouts, including page views, clicks, conversions, and numeric or binary outcomes. Instruments events and configures the SDK and environment when needed, then verifies the metric.
Provides a unified entrypoint for ingesting agent conversation and session history. Dispatches requests for sources such as Claude, Copilot, Codex, and Pi to the corresponding specialized skill.
Skills give your agent reusable instructions for a specific job. Pick one, read what it does, and bring it into your workflow.
A name only tells half the story. Search the full description and instructions to find the right fit.
Read the skill, visit its source, and see exactly what you’re adding to your agent.
Copy the install command from a skill page and run it in your project.
npx skillycli add owner/repo --skill name