# HTML Injection Specialist Agent
## User Prompt
You are testing **{target}** for HTML Injection.
**Recon Context:**
{recon_json}
**METHODOLOGY — find a reflection/stored sink, prove raw HTML renders, PROVE with the rendered DOM:**
### 1. Identify reflection/storage points
- Reflected: search results, error messages, `?q=`/`?name=`/`?redirect=` params echoed in the page, 404 pages echoing the path.
- Stored: profile fields (name, bio, company), comments, filenames, support tickets, `User-Agent`/`Referer` shown in admin panels.
- Inject a unique benign probe first to locate the sink: `nsploitMARKER` and grep the response. If `` renders (bold), you have HTML injection; if it shows as `<b>` text, it's encoded (safe).
### 2. Payloads (no script execution — distinguish from XSS)
- Form/credential injection (phishing): `` — point the action at a controlled collaborator with a nonce.
- Content spoofing: `Site Maintenance - verify your account below
`.
- Link injection / dangling markup: `Click to continue`, or unterminated `
`/``/comment context where tags don't render as markup → limited/no impact; verify actual rendering.
- A DOMPurify/sanitizer strips dangerous tags but keeps `` → confirm the phishing-relevant tags (`