From communitytools
Tests for injection vulnerabilities including SQL, NoSQL, OS command, SSTI, XXE, and LDAP/XPath across input vectors. Guides detection, exploitation, escalation, and PoC for security audits.
npx claudepluginhub transilienceai/communitytoolsThis skill uses the workspace's default tool permissions.
Test for injection vulnerabilities across all input vectors. Covers SQL, NoSQL, Command, SSTI, XXE, and LDAP injection.
reference/nosql-injection-advanced.mdreference/nosql-injection-cheat-sheet.mdreference/nosql-injection-quickstart.mdreference/nosql-injection-resources.mdreference/os-command-injection-cheat-sheet.mdreference/os-command-injection-quickstart.mdreference/sql-injection-advanced.mdreference/sql-injection-quickstart.mdreference/sql-injection.mdreference/ssti-advanced.mdreference/ssti-cheat-sheet.mdreference/ssti-quickstart.mdreference/ssti-resources.mdreference/xxe-cheat-sheet.mdreference/xxe-quickstart.mdAssesses SQL injection vulnerabilities in web apps via error-based, boolean-blind, and time-based tests using SQLMap, Burp Suite, and manual payloads to validate input sanitization.
Tests APIs for SQL, NoSQL, command, LDAP injection, and SSRF via inputs. Crafts payloads targeting databases and backends for authorized pentesting.
Identifies common web vulnerability patterns like SQL injection, command injection, XSS, and OWASP Top 10 during whitebox pentesting and code reviews.
Share bugs, ideas, or general feedback.
Test for injection vulnerabilities across all input vectors. Covers SQL, NoSQL, Command, SSTI, XXE, and LDAP injection.
| Type | Key Vectors |
|---|---|
| SQL Injection | In-band (union, error), Blind (boolean, time), Out-of-band |
| NoSQL Injection | Operator injection, JavaScript injection, aggregation pipeline |
| Command Injection | OS command separators, blind techniques, out-of-band |
| SSTI | Template engine detection, sandbox escape, RCE chains |
| XXE | Entity expansion, SSRF via XXE, blind XXE, parameter entities |
| LDAP/XPath | Filter manipulation, authentication bypass |
reference/sql-injection*.md - SQL injection techniquesreference/nosql-injection*.md - NoSQL injection techniquesreference/os-command-injection*.md - OS command injectionreference/ssti*.md - Server-side template injectionreference/xxe*.md - XML external entity injection