--- name: hunt-xss description: XSS hunting - reflected, stored, DOM-based. Marker discipline to avoid false positives. Blind-XSS beacons for stored contexts. SVG/markdown/redirect vectors. Wiki-first, FIND schema output. --- # Hunt: XSS **Assumes `hunt-core`** for the scope gate, two-account rule, confirmation gate, enumeration limits, stop conditions, wiki protocol, FIND output, and Deadends. Marker discipline (unique 8+ char canaries, check the baseline first) lives in hunt-core. ## Wiki ``` qmd_query "XSS cross-site scripting DOM CSP bypass sanitizer" via wiki-search MCP ``` Hub: [[web-moc]] (live web index). Primary page: [[xss]]. Payload arsenals: `wiki/payloads/{xss,prototype-pollution}.md`. Related client-side vectors: [[dangling-markup]] (scriptless HTML-injection exfil when script tags are blocked), [[xssi]] (JSONP/script-inclusion info leak), [[browser-extension-attacks]] (content-script/message-passing injection). ## Confirmation gate NOT confirmation: payload URL-encoded or HTML-encoded in response, ` ./x?c='+document.cookie)>