skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
transilienceai/communitytools167 installs

injection

Injection vulnerability testing - SQL, NoSQL, OS Command, SSTI, XXE, and LDAP/XPath injection techniques.

How do I install this agent skill?

npx skills add https://github.com/transilienceai/communitytools --skill injection
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubfail

    The analyzed skill contains only markdown documentation, cheat sheets, and quickstart guides for vulnerability testing (SQL, NoSQL, OS Command, SSTI, XXE, and LDAP/XPath injection). No active code or executables are shipped with this skill. The automated scanner alerts regarding trojans or reverse shell patterns are false positives triggered by the text-based security payloads included as educational or reference examples within the markdown files.

  • Socketfail

    31 alerts: gptSecurity, gptAnomaly, gptMalware

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

Injection

Test for injection vulnerabilities across all input vectors. Covers SQL, NoSQL, Command, SSTI, XXE, and LDAP injection.

Techniques

TypeKey Vectors
SQL InjectionIn-band (union, error), Blind (boolean, time), Out-of-band
NoSQL InjectionOperator injection, JavaScript injection, aggregation pipeline
Command InjectionOS command separators, blind techniques, out-of-band
SSTITemplate engine detection, sandbox escape, RCE chains
XXEEntity expansion, SSRF via XXE, blind XXE, parameter entities
LDAP/XPathFilter manipulation, authentication bypass

Workflow

  1. Identify injection points (parameters, headers, cookies, JSON fields)
  2. Detect injection type with minimal probes
  3. Exploit with context-appropriate payloads
  4. Escalate (data extraction, RCE, file read)
  5. Capture evidence and write PoC

Reference

  • reference/sql-injection*.md - SQL injection techniques
  • reference/nosql-injection*.md - NoSQL injection techniques
  • reference/os-command-injection*.md - OS command injection
  • reference/ssti*.md - Server-side template injection
  • reference/xxe*.md - XML external entity injection
  • reference/ldap-injection-quickstart.md - LDAP filter injection: detection, auth bypass, blind boolean extraction via (description=PREFIX*) chaining
  • reference/xpath-injection-quickstart.md - XPath injection (CWE-643): lxml/Java/Node sinks, ' or '1'='1' or 'a'='b boolean oracle, blind char-by-char extraction recipe

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/transilienceai/communitytools/injection">View injection on skillZs</a>