injection

Identify and assess injection vulnerabilities across SQL, NoSQL, OS command, SSTI, XXE, and LDAP/XPath contexts.

3|1|Updated May 26, 2026
One-click install
npx skills add https://github.com/LeoWSY-hashblue/-communitytools-custom --skill injection-leowsy-hashblue
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: injection
Source: https://github.com/LeoWSY-hashblue/-communitytools-custom/tree/main/skills/injection
Command: npx skills add https://github.com/LeoWSY-hashblue/-communitytools-custom --skill injection-leowsy-hashblue

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Injection vulnerability testing across SQL, NoSQL, OS Command, SSTI, XXE, and LDAP/XPath contexts helps security teams identify weaknesses before attackers exploit them.

Core Features & Use Cases

  • Map and classify injection surfaces across databases, templating engines, and protocols.
  • Provide structured workflows for detection, verification, and safe PoC development.
  • Apply to security assessments, bug bounty scopes, and CTF learning scenarios.

Quick Start

Identify an injection surface in a target application and propose a minimal, non-disruptive PoC payload.

Frequently Asked Questions about injection

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I test for SQL and NoSQL injection vulnerabilities in web applications?

To test for injection vulnerabilities, this Skill maps injection surfaces across databases, templating engines, and protocols, guiding you through discovery, verification, and safe PoC development workflows.

What is the best way to identify SSTI and XXE attack surfaces?

The best way to identify SSTI and XXE attack surfaces is by classifying injection points across templating engines and protocols, applying structured workflows to detect and verify weaknesses before attackers exploit them.

Can I use this for LDAP and XPath injection testing in authentication flows?

Yes, you can test LDAP and XPath injection across authentication flows and data entry points, assessing vulnerabilities and developing safe proof-of-concept payloads for security research.

How do I create a minimal PoC payload for OS command injection?

To create a minimal PoC payload for OS command injection, identify the target injection surface and propose a non-disruptive payload using the structured verification workflows provided for safe research and testing.

Does this injection testing approach work for bug bounty and CTF scenarios?

Yes, this injection testing approach works for bug bounty scopes and CTF learning scenarios, providing reusable workflows and reference materials designed for safe research, documentation, and tooling integration.

When should I not use automated injection payloads during security testing?

You should avoid automated injection payloads when they risk disruption; instead, use this Skill's structured workflows to propose minimal, non-disruptive PoC payloads for safe verification and documentation.