Covers secondary-source DOM XSS rules using cookie, storage, window.name, hash route, postMessage, and referrer-driven setups.
No secondary source primed yet.