pentest-injection-engine
Systematically test authorized targets for SQL, XSS, SSTI, XXE, command, and request-smuggling injection classes.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Systematically test authorized targets for SQL, XSS, SSTI, XXE, command, and request-smuggling injection classes.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Plan and orchestrate authorized Nmap host discovery, port and service enumeration, NSE profiling, and reporting artifacts for in-scope targets.
Assess Active Directory identity attack paths including roasting, relay, and delegation abuse.
Test APIs against OWASP API Security Top 10 including discovery, auth abuse, and protocol-specific checks.
Test authentication and session management controls for bypass and account takeover scenarios.
Set up authorized C2 simulation workflows and measure defensive detection outcomes.
Assess AWS, Azure, and GCP controls for IAM escalation and cloud service exposure.
| name | pentest-injection-engine |
| description | Systematically test authorized targets for SQL, XSS, SSTI, XXE, command, and request-smuggling injection classes. |
Validate injection exploitability and capture payload-level evidence.
python skills/pentest-injection-engine/scripts/injection_engine.py --scope scope.json --target <target> --input <path> --output <path> --format json --dry-run
injection-findings.jsonxss-payloads-that-fired.jsoninjection-report.jsonreferences/tools.mdskills/autonomous-pentester/shared/scope_schema.jsonskills/autonomous-pentester/shared/finding_schema.jsonWARNING AUTHORIZED USE ONLY
This skill executes real security testing tools against live targets.
Use only with written authorization.