Skip to main content
Exécutez n'importe quel Skill dans Manus
en un clic

command-injection-rce

// Turn suspected OS command injection (a parameter that lands in a shell or a child process) into proof of remote code execution via an OAST callback, plus one safe demonstration of follow-on impact (read a file, list users, env dump). Use when a parameter feeds an exec/spawn/system call, when payloads with $(), `` ` ``, `;`, `|`, `&&` cause response differences, or when audit flags CWE-78 / CWE-77. Never sends destructive commands.

$ git log --oneline --stat
stars:586
forks:90
updated:23 mai 2026 à 16:43
SKILL.md
readonly