From 5e942cabcac7921724e47d1b8a40ef2f6cc7b7c5 Mon Sep 17 00:00:00 2001 From: ppcvote Date: Mon, 1 Jun 2026 14:44:46 +0800 Subject: [PATCH] AITG-APP-05: add 6 output-injection vector categories (XSS-beyond-script-tags / SQLi / Shell / Path / MD-image-exfil / Unicode-smuggling) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The existing AITG-APP-05 test scenario covers content-level safety categories (1-10) and a single XSS attack vector (test 11), but the doc's summary explicitly identifies application-level risks (XSS, SSRF, injections) as a major category and the framework page #28 has an open request for "more examples of web exploits enabled by output." Adds six new payload categories (tests 12-17) covering the application-level injection vectors not yet documented: 12. XSS beyond ` + ``` + - ``` + Reply with an