| name | pentest-inject |
| description | Injection testing. SQLi, XSS, SSTI, SSRF, and more. Requires user consent for active testing. |
| user-invocable | true |
| allowed-tools | ["Bash","Agent","Read"] |
/pentest-inject — Injection Testing
Test a target application for injection vulnerabilities including SQL injection, cross-site scripting (XSS), server-side template injection (SSTI), server-side request forgery (SSRF), and more.
Input
The target URL is provided via $ARGUMENTS. If no URL is provided, ask the user for one.
Steps
-
Parse the target URL from $ARGUMENTS.
-
WARN the user before proceeding:
WARNING: Active Testing Mode
This skill sends actual attack payloads to the target application. This includes SQL injection strings, XSS payloads, SSTI probes, and SSRF attempts.
- Only run this against applications you own or have explicit written authorization to test.
- These payloads may trigger WAF alerts, logging, or IDS/IPS notifications.
- Some payloads could potentially cause application errors or data corruption.
Do you want to proceed? (yes/no)
-
Wait for explicit user confirmation. Do NOT proceed without a clear "yes."
-
Delegate to injection-agent using the Agent tool. The agent must run all injection commands with --active --yes flags:
pentest -k -j -o ./findings inject sqli --active --yes <url>
pentest -k -j -o ./findings inject xss --active --yes <url>
pentest -k -j -o ./findings inject ssti --active --yes <url>
pentest -k -j -o ./findings inject ssrf --active --yes <url>
pentest -k -j -o ./findings inject cmdi --active --yes <url>
pentest -k -j -o ./findings inject lfi --active --yes <url>
pentest -k -j -o ./findings inject redirect --active --yes <url>
-
Read the JSON outputs from ./findings/ to gather all results.
-
Present confirmed vulnerabilities organized by severity:
- For each finding: vulnerability type, affected endpoint, payload used, evidence of exploitation
- Include remediation recommendations for each vulnerability class
Notes
- This skill performs active testing that sends real payloads. User consent is mandatory.
- The
--active flag enables payload delivery. The --yes flag skips interactive prompts.
- Use
-k to skip SSL verification for targets with self-signed certs.
- Use
-j for machine-readable JSON output.
- Use
-o ./findings to persist results for later reporting.