command-injection-rce
Turn suspected OS command injection (a parameter that lands in a shell or a child process) into proof of remote code execution via an OAST callback, plus one safe demonstration of follow-on impact (read a file, list users, env dump). Use when a parameter feeds an exec/spawn/system call, when payloads with $(), `` ` ``, `;`, `|`, `&&` cause response differences, or when audit flags CWE-78 / CWE-77. Never sends destructive commands.
Details
- Path
- internal/resources/olium/skills/command-injection-rce/SKILL.md
- License
- MIT
- Allowed tools
- 10
Allowed tools
query_recordsinspect_recordreplay_requestoast_mintoast_pollattack_kitreport_findingupdate_findingrememberupdate_plan