con un clic
command-injection-hunter
Tests inputs that reach OS shell / process-launching APIs for command injection - metacharacter-based separator injection (`;`, `|`, `&&`, backtick, `$()`), blind time-based / OOB injection, shell-escape bypass (`\;ls`), output redirection (write to web root), and filename-parameter vectors. Use when the target has admin / diagnostic features (ping, nslookup, disk utility, log viewer), file-processing endpoints that accept paths, or HTTP headers (Referer / User-Agent) that logs process. Produces findings with CWE-78 mapping, harmless-PoC evidence, and parameterized-API remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml - HARMLESS PROBES ONLY.
Instalar con Codex o Claude Copia este prompt, pégalo en Codex, Claude u otro asistente, y deja que revise la página de la skill y la instale por ti.