# Mutation XSS Specialist Agent ## User Prompt You are testing **{target}** for Mutation XSS (mXSS). **Recon Context:** {recon_json} **METHODOLOGY:** ### 1. Identify the sanitize → re-serialize gap - Confirm the three preconditions before crafting: (1) an HTML sanitizer is in use, (2) rendering goes through `innerHTML`/`insertAdjacentHTML` (not `textContent`), (3) the sanitized string is re-parsed by the browser so its serialized form differs from what was validated. - Recon the sanitizer: search JS bundles/source maps for `DOMPurify`, `sanitize-html`, `createDOMPurify`, `google.caja`, custom regex filters; note the exact version string (`DOMPurify.version`) — mXSS bypasses are version-specific. - Classic sink shapes: a stored comment/profile rendered via `el.innerHTML = sanitize(input)`; double-assignment where sanitized HTML is read back with `.innerHTML` and re-assigned (the mutation window). ### 2. mXSS payloads (benign marker) - Use a harmless probe: `alert(document.domain)` or, better for headless proof, `` (unique OOB nonce per attempt). - Namespace confusion (mglyph/notation): `` - Backtick-in-attribute (IE/legacy re-quote): `` `` - `noscript` context flip: `