en un clic
command-injection-hunter
Tests inputs that reach OS shell / process-launching APIs for command injection - metacharacter-based separator injection (`;`, `|`, `&&`, backtick, `$()`), blind time-based / OOB injection, shell-escape bypass (`\;ls`), output redirection (write to web root), and filename-parameter vectors. Use when the target has admin / diagnostic features (ping, nslookup, disk utility, log viewer), file-processing endpoints that accept paths, or HTTP headers (Referer / User-Agent) that logs process. Produces findings with CWE-78 mapping, harmless-PoC evidence, and parameterized-API remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml - HARMLESS PROBES ONLY.
Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.