SecFathy/xss-specialist

KEV-gated continual-learning XSS specialist with execution-authoritative browser verification

Open original source ↗

From the publisher

README & documentation

Source preview

Read the project’s overview, installation instructions and usage examples. The original README is the source of truth.

Can a small language model become a deep XSS expert through gated continual learning — and can a browser oracle turn its reasoning into evidence-backed, hard-to-fool findings? We built it, measured it honestly, and report the negatives. xss-specialist is a research prototype with two halves. The first is an offline study: can a small (8B) open model be specialized into a deep XSS reasoner using retrieval, LoRA fine-tuning, and a KEV-gated continual-learning pipeline where a frozen decision model (Kev-4B) decides what knowledge is even allowed to reach the weights? The second is a live, authorized assessment system that crawls a target in scope, plans marker-first, non-destructive probes, and confirms XSS with a headless-browser oracle — where execution, not model confidence, is the sole authority for a CONFIRMED finding. The most important results are the honest negatives: a specialist model can fix false positives and execution-context accuracy but cannot solve near-miss…

SecFathy/xss-specialist on GitHub A short preview, not the full document.

Read the full README ↗ · Preview checked 2026-10-03T13:11:37.212Z

Inside the original README — Document outline
  1. xss-specialist
  2. A Kev-style XSS decision model + an execution-authoritative live assessment system
  3. Table of contents
  4. The one-paragraph version
  5. Why this exists
  6. Two systems, one repo
  7. Kev-style XSS decision model
  8. Headline results
  9. Live assessment — XSS-LiveBench-v2 (102 cases, final frozen run)
  10. The ablation that matters: the oracle, not the model, drives quality
  11. Real-world demo (public sandbox)
  12. The research: KEV-gated continual learning

Headings are captured from the source. Links open the publisher’s document, not a locally hosted copy.

Links from the README

References supplied by the publisher, not independently verified endorsements. Check the destination before downloading files or entering credentials.

Documentation belongs to its respective authors. A listing is not a grant of reuse or training rights. Confirm the document’s own terms at the source.

What this repository does

KEV-gated continual-learning XSS specialist with execution-authoritative browser verification

Repository facts

Owner
SecFathy
Primary language
Python
Stars
155
Forks
10
Open issues + pull requests
0
License
Not reported — inspect the license file
Archived
No
Default branch
main
Created
2026-09-27T19:11:33.000Z
Last push
2026-09-28T09:18:40.000Z

Topics and intended use

No topics were included in the latest source metadata.

Review the README for scope, installation, examples and limitations. We do not run repository code or certify it.

Evaluate before installing

Review licensing and dependencies, inspect recent commits and unresolved issues, and test in an isolated environment before production use. Stars and forks alone cannot answer these questions.

README and project files

Issues and maintenance discussion

Releases and changelog

Source and freshness

Source: GitHub. Metadata observed 2026-10-03T12:05:37.640Z. Daily imports are snapshots, not real-time monitoring.

Popularity and source listings do not establish security, suitability, licensing rights or benchmark performance.

Open original source

Related repositories

public-apis/public-apis

EbookFoundation/free-programming-books

donnemartin/system-design-primer

vinta/awesome-python

practical-tutorials/project-based-learning

NousResearch/hermes-agent