Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Client-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution.
.claude/skills/transilienceai-client-side/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-07 | ✗→✓ | ▲ Improved | 13% | 0% |
| case-08 | ✗→✓ | ▲ Improved | -52% | 0% |
| case-10 | ✗→✓ | ▲ Improved | -49% | 0% |
| case-18 | ✗→✓ | ▲ Improved | 2% | 0% |
| case-04 | ✓→✗ | ▼ Worse | 21% | 0% |
Test for client-side vulnerabilities across modern web applications and SPAs.
| Type | Key Vectors | |------|-------------| | XSS | Reflected, Stored, DOM-based, framework-specific (React, Vue, Angular) | | CSRF | Token bypass, SameSite cookie bypass, cross-origin requests | | CORS | Misconfigured origins, null origin, wildcard credentials | | Clickjacking | Frame-based, drag-and-drop, multi-step | | DOM-based | DOM sinks, source/sink analysis, JavaScript URL schemes | | Prototype Pollution | Client-side gadgets, server-side pollution, property injection |
reference/xss*.md - XSS bypass techniques and exploitationreference/csrf*.md - CSRF techniques and bypassesreference/cors*.md - CORS misconfiguration testingreference/clickjacking*.md - Clickjacking techniquesreference/dom*.md - DOM-based vulnerability testingreference/prototype-pollution*.md - Prototype pollution techniquesOther measured skills in the registry, with their headline benchmark lift.