skillrank_skill wgpsec/cross-domain-attack-chainMIT · open registry

skill detail

← registry

Cross Domain Attack Chain

wgpsec/cross-domain-attack-chain

Web 与 AI 跨域攻击链方法论。当目标系统同时包含传统 Web 应用和 AI/LLM 组件、 需要评估 Web 漏洞对 AI 系统的影响或 AI 漏洞对 Web 系统的影响时触发。 覆盖双向攻击链: Web→AI(XSS 窃取对话/SSRF 调用模型 API/SQLi 污染 RAG/文件上传 RAG 投毒) 和 AI→Web(注入生成存储型 XSS/Agent 执行 SQL 命令/工具读取敏感文件/沙箱逃逸 RCE)。

communityprovisionalbackendwebllmxss

skillrank score

███████░░░░░░░░░43

SkillRank score blends community stars, real usage, and our eval lift; provisional until a skill is evaluated -- so popularity alone can't reach the top tier.

source

1.6k

wgpsec/AboutSecurity

skills/ai-security/cross-domain-attack-chain

open on GitHub ▸

eval status

eval pending

Success delta, token delta, and trial count are not available yet. No eval number is shown until this skill has measured results.

install

$ skillrank install wgpsec/cross-domain-attack-chain
$ curl -fsSL skillrank.dev | sh