Review agent · Web & injection
Cross-site scripting (XSS)
Checks whether untrusted data is rendered into HTML or JavaScript without contextual encoding.
Illustrative example of how this agent reviews a finding.
Why this agent matters
XSS lets an attacker run script in your users' browsers — stealing sessions, acting as the user, or rewriting the page. CWE-79 has topped the CWE Top 25 in recent years.
Modern frameworks escape by default, so most XSS hits from scanners are on static or already-escaped values. The real bugs hide in the escape hatches. This agent separates the two so the dangerouslySetInnerHTML that matters doesn't get lost among the ones that don't.
What it checks
- Raw HTML sinks: innerHTML, dangerouslySetInnerHTML, v-html
- Templates with autoescaping disabled
- Reflected or stored input echoed back into a page
- Values placed into script, attribute or URL contexts
When it marks a finding as a likely false positive
- The rendered value is static or authored by you, not by users
- The value is encoded for its output context by the framework
The fix it suggests
- Contextual escaping or the framework's safe rendering
- A strict Content-Security-Policy
- Removing the raw-HTML sink or sanitizing with a vetted library
Scope and limits
This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.
Common questions
Will it flag every use of dangerouslySetInnerHTML?
The scanner will; the agent then checks where the HTML comes from. Static, server-built markup is marked a likely false positive with the reason.
Related agents
- SQL injection — Decides whether attacker-controlled input actually reaches a SQL or NoSQL query unparameterized.
- Server-side request forgery (SSRF) — Checks whether a server-side request can be pointed at a host the attacker chooses.
- Command & code injection — Checks whether user input reaches a shell, eval or template-evaluation sink.
See all 20 review agents → · Agent setup reviewer · How the pipeline works
Run the Cross-site scripting (XSS) agent on your repository
100 free credits, no credit card. Every finding comes with a verdict and a fix.
Get started free