injection
Injection vulnerability testing - SQL, NoSQL, OS Command, SSTI, XXE, and LDAP/XPath injection techniques.
How do I install this agent skill?
npx skills add https://github.com/transilienceai/communitytools --skill injectionIs this agent skill safe to install?
- Gen Agent Trust Hubfail
The analyzed skill contains only markdown documentation, cheat sheets, and quickstart guides for vulnerability testing (SQL, NoSQL, OS Command, SSTI, XXE, and LDAP/XPath injection). No active code or executables are shipped with this skill. The automated scanner alerts regarding trojans or reverse shell patterns are false positives triggered by the text-based security payloads included as educational or reference examples within the markdown files.
- Socketfail
31 alerts: gptSecurity, gptAnomaly, gptMalware
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Injection
Test for injection vulnerabilities across all input vectors. Covers SQL, NoSQL, Command, SSTI, XXE, and LDAP injection.
Techniques
| Type | Key Vectors |
|---|---|
| SQL Injection | In-band (union, error), Blind (boolean, time), Out-of-band |
| NoSQL Injection | Operator injection, JavaScript injection, aggregation pipeline |
| Command Injection | OS command separators, blind techniques, out-of-band |
| SSTI | Template engine detection, sandbox escape, RCE chains |
| XXE | Entity expansion, SSRF via XXE, blind XXE, parameter entities |
| LDAP/XPath | Filter manipulation, authentication bypass |
Workflow
- Identify injection points (parameters, headers, cookies, JSON fields)
- Detect injection type with minimal probes
- Exploit with context-appropriate payloads
- Escalate (data extraction, RCE, file read)
- Capture evidence and write PoC
Reference
reference/sql-injection*.md- SQL injection techniquesreference/nosql-injection*.md- NoSQL injection techniquesreference/os-command-injection*.md- OS command injectionreference/ssti*.md- Server-side template injectionreference/xxe*.md- XML external entity injectionreference/ldap-injection-quickstart.md- LDAP filter injection: detection, auth bypass, blind boolean extraction via(description=PREFIX*)chainingreference/xpath-injection-quickstart.md- XPath injection (CWE-643): lxml/Java/Node sinks,' or '1'='1' or 'a'='bboolean oracle, blind char-by-char extraction recipe
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/transilienceai/communitytools/injection">View injection on skillZs</a>