Insecure output handling (LLM → sink)
SkillDatabases & dataExploit apps that trust LLM output, pass model text unsanitized into XSS sinks, SQL, shell, code, or downstream calls. Load when LLM output is rendered as HTML/markdown, executed, or fed to another system. Signals: chatbot output shown with innerHTML/dangerouslySetInnerHTML, "run this code", LLM-generated queries/commands, agent output used in eval/exec.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Insecure output handling (LLM → sink) skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/ai-ml/ai-insecure-output-handling/SKILL.md and read by ahel’s review.
When it applies
The app treats LLM output as trusted and passes it into a dangerous sink — rendered as HTML,
executed as code/SQL/shell, or forwarded to another API. The model becomes an injection vector,
especially when its input is attacker-influenced (→ chain with ai-prompt-injection).
Why it works
Developers trust their own model's output, but it's just text — and an attacker can steer it via
prompt injection. If that text lands in innerHTML, eval, a SQL string, a shell command, or a
system call without sanitization, you get XSS/RCE/SQLi through the LLM.
Method
- Find the sink: where does model output go? HTML render (
innerHTML, markdown→HTML,dangerouslySetInnerHTML), code exec (eval, code interpreter), DB (LLM-built query), shell, or another service call. - Get the model to emit a payload: via direct or indirect prompt injection, make the output
contain
<img src=x onerror=alert(document.domain)>, ajavascript:link, SQL, or a command. - Route to impact:
- Rendered output → stored/reflected XSS (fires for the user or others viewing the chat).
- Code-interpreter/tool → RCE (→
ai-agent-tool-abuse). - LLM-generated SQL/commands executed → SQLi / command injection.
- Markdown exfil: model emits
→ beacons data on render.
Gotchas
- The bug is in the app's handling, not the model — the fix is output encoding/sandboxing, same as any injection.
- Stored XSS via chat history hits every viewer — high impact, easy to miss.
- Combine with prompt injection to reliably control the output; prove real execution, not just odd text.
Verify success
Model-produced content executes in a sink — XSS firing in the app's origin, code/command execution, or injected SQL — traceable to LLM output.
References
OWASP LLM Top 10 (2025) LLM05; PortSwigger "web LLM attacks"; markdown-exfil write-ups.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
ai-insecure-output-handling- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · thedaviddias
The pick for JavaScriptmodern-javascript-patterns
Skill · wshobson
The pick for JavaScriptlark-markdown
Skill · larksuite
The pick for Markdownmarkdown-mermaid-writing
Skill · k-dense-ai
The pick for Markdownowasp-security
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)