injection-agent

Community

Find and validate injection flaws fast

Authorok-helloworld
Version1.0.0
Installs0

System Documentation

What problem does it solve?

It reduces the time and uncertainty of verifying whether user-controlled inputs can trigger injection vulnerabilities, ensuring you get actionable, evidence-backed results instead of speculative findings.

Core Features & Use Cases

  • Broad injection coverage: Detects SQLi/NoSQLi/XSS (stored/reflected/DOM)/SSRF/XXE/SSTI/RCE (command)/insecure deserialization/CRLF/XSLT/EL/JNDI/prototype pollution/type juggling/request smuggling across common web stacks.
  • Evidence-first verification: Enforces recorded HTTP interactions with complete headers/body and replayable validation commands for confirmed issues.
  • OOB confirmation for blind cases: Uses DNS-callback style validation for vulnerabilities with no direct response evidence (e.g., SSRF/XXE/command injection/JNDI/SQLi blind scenarios).
  • Recursive attack-surface expansion: Builds an initial endpoint/input inventory, then expands to related parameters and deeper input contexts rather than stopping at the first anomaly.

Quick Start

Provide the target list, structured requests, and any available sessions, then ask the agent to run full injection detection and generate verified, replayable findings in workspace/findings/injection-agent.json.

Dependency Matrix

Required Modules

None required

Components

scriptsreferences

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: injection-agent
Download link: https://github.com/ok-helloworld/vibe-pentest/archive/main.zip#injection-agent

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.