Skip to content

command-injection-rce

SkillMITby vigolium

Turn suspected OS command injection (a parameter that lands in a shell or a child process) into proof of remote code execution via an OAST callback, plus one safe demonstration of follow-on impact (read a file, list users, env dump). Use when a parameter feeds an exec/spawn/system call, when payloads with $(), `` ` ``, `;`, `|`, `&&` cause response differences, or when audit flags CWE-78 / CWE-77. Never sends destructive commands.

Repository Source folder

Details

Path
internal/resources/olium/skills/command-injection-rce/SKILL.md
License
MIT
Allowed tools
10

Allowed tools

query_recordsinspect_recordreplay_requestoast_mintoast_pollattack_kitreport_findingupdate_findingrememberupdate_plan

FAQ