This skill should be used when the user asks to "test for HTML injection", "inject HTML into web pages", "perform HTML injection attacks", "deface web applications", or "test content injection vulnerabilities". It provides comprehensive HTML injection attack techniques and testing methodologies.
Scanned 9/4/2026
Install to Claude Code
npx -y skills add gabrielmoreira/agent-skills-mirror --skill html-injection-testing --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Html Injection Testing?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/gabrielmoreira-html-injection-testing-agent-skills-mirror)More formats (shields.io, HTML) on the badges page.
---
name: HTML Injection Testing
description: This skill should be used when the user asks to "test for HTML injection", "inject HTML into web pages", "perform HTML injection attacks", "deface web applications", or "test content injection vulnerabilities". It provides comprehensive HTML injection attack techniques and testing methodologies.
metadata:
author: zebbern
version: 4.1.0-fractal
---
# HTML Injection Testing
## Purpose
Identify and exploit HTML injection vulnerabilities that allow attackers to inject malicious HTML content into web applications. This vulnerability enables attackers to modify page appearance, create phishing pages, and steal user credentials through injected forms.
## Prerequisites
## 🧠 Knowledge Modules (Fractal Skills)
### 1. [Required Tools](./sub-skills/required-tools.md)
### 2. [Required Knowledge](./sub-skills/required-knowledge.md)
### 3. [Phase 1: Understanding HTML Injection](./sub-skills/phase-1-understanding-html-injection.md)
### 4. [Phase 2: Identifying Injection Points](./sub-skills/phase-2-identifying-injection-points.md)
### 5. [Phase 3: Basic HTML Injection Testing](./sub-skills/phase-3-basic-html-injection-testing.md)
### 6. [Phase 4: Types of HTML Injection](./sub-skills/phase-4-types-of-html-injection.md)
### 7. [Phase 5: Phishing Attack Construction](./sub-skills/phase-5-phishing-attack-construction.md)
### 8. [Phase 6: Defacement Payloads](./sub-skills/phase-6-defacement-payloads.md)
### 9. [Phase 7: Advanced Injection Techniques](./sub-skills/phase-7-advanced-injection-techniques.md)
### 10. [Phase 8: Bypass Techniques](./sub-skills/phase-8-bypass-techniques.md)
### 11. [Phase 9: Automated Testing](./sub-skills/phase-9-automated-testing.md)
### 12. [Phase 10: Prevention and Remediation](./sub-skills/phase-10-prevention-and-remediation.md)
### 13. [Common Test Payloads](./sub-skills/common-test-payloads.md)
### 14. [Injection Contexts](./sub-skills/injection-contexts.md)
### 15. [Encoding Types](./sub-skills/encoding-types.md)
### 16. [Attack Limitations](./sub-skills/attack-limitations.md)
### 17. [Testing Considerations](./sub-skills/testing-considerations.md)
### 18. [Severity Assessment](./sub-skills/severity-assessment.md)
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!