hunting-nosql-operator-and-where-injection
Hunt NoSQL injection where untrusted input becomes query structure rather than a bound value: a request body whose keys turn into query operators, a value that arrives as an object instead of a scalar, or input reaching a server-side JavaScript evaluation such as $where, a mapReduce function, or an aggregation expression. Covers document stores where a filter built from a request object lets the caller inject comparison operators, always-true conditions, or code, and key-value or wide-column stores where input shapes the query language. Use when data access takes structured input from the request into a query filter or a server-side expression. The untrusted value that becomes an operator or an expression is the source, the query or evaluation call is the sink, and the missing type and shape check is the bug.
Source facts
- Repository
- UnboundCompute/security-agent-skills
- Last source activity
- August 26, 2026 at 07:09
- Detected SKILL.md language
- English
- Stars
- 4
- Forks
- 2
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.