| name | cyber-exploiting-api-injection-vulnerabilities |
| description | [LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP injection, and Server-Side Request Forgery (SSRF) through API parameters, headers, and request bodies. The tester crafts malicious payloads targeting different backend technologies and injection contexts to extract data, execute commands, or access internal services. Maps to OWASP API8:202 |
| hide | true |
YURI skill adapter
Authoritative source: .claude/skills-labgated/cyber-exploiting-api-injection-vulnerabilities/SKILL.md
Authoritative source SHA-256: 6956cbb1bb40973bf144ac7297a28211e5da248db4a181b72b78b3cf784a7528
AUTHORIZED-LAB ONLY. Offensive/dual-use capability. Use exclusively against systems you own or have explicit written authorization to test. Owner-authorized metadata discovery does not authorize runtime actions; use requires an explicit authorized-engagement decision.
Source class: labgated
Owner-authorized discovery: true
Runtime/action authorization: false
Risk gate (registry metadata): "offensive/dual-use — authorized-lab gate"
Discovery does not authorize execution. Obtain explicit current-task authorization before any offensive or dual-use action.
Before acting, read the authoritative source file above completely from beginning to end. If the governed source is absent, run node _SYSTEM/Scripts/skill-recall.mjs --show cyber-exploiting-api-injection-vulnerabilities and read its complete verified output. Follow that source as the skill body; this adapter is a non-authoritative metadata-and-pointer projection.