sk Skill · mukul975
performing-content-security-policy-bypass
Analyze Content-Security-Policy headers and bypass them to achieve cross-site scripting by exploiting unsafe-inline/unsafe-eval, whitelisted JSONP endpoints, base-uri and form-action gaps, and nonce/hash weaknesses, then exfiltrate data even without script-src control. Use during web application security assessments or bug bounty hunting when XSS is found but blocked by CSP, or when auditing CSP header configuration…
Open on skills.sh ↗read 2026-09-17
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 0
Pythonpolicy-misconfigurationjsonpscript-injectionbashxssnonce-bypasscontent-security-policycsp-bypass
- Host repository
- mukul975/Anthropic-Cybersecurity-Skills
- Version
- 1.0
- Licence
- Apache-2.0
- Host stars
- 33k
- Host language
- Python