Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Injection vulnerability testing - SQL, NoSQL, OS Command, SSTI, XXE, and LDAP/XPath injection techniques.
.claude/skills/transilienceai-injection/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-13 | ✗→✓ | ▲ Improved | 18% | 0% |
| case-22 | ✗→✓ | ▲ Improved | 35% | 0% |
| case-11 | ✓→✗ | ▼ Worse | 7% | 0% |
| case-16 | ✓→✗ | ▼ Worse | 50% | 0% |
| case-03 | ✓→✓ | = Same ✓ | 54% | 0% |
Test for injection vulnerabilities across all input vectors. Covers SQL, NoSQL, Command, SSTI, XXE, and LDAP injection.
| Type | Key Vectors | |------|-------------| | SQL Injection | In-band (union, error), Blind (boolean, time), Out-of-band | | NoSQL Injection | Operator injection, JavaScript injection, aggregation pipeline | | Command Injection | OS command separators, blind techniques, out-of-band | | SSTI | Template engine detection, sandbox escape, RCE chains | | XXE | Entity expansion, SSRF via XXE, blind XXE, parameter entities | | LDAP/XPath | Filter manipulation, authentication bypass |
reference/sql-injection*.md - SQL injection techniquesreference/nosql-injection*.md - NoSQL injection techniquesreference/os-command-injection*.md - OS command injectionreference/ssti*.md - Server-side template injectionreference/xxe*.md - XML external entity injectionreference/ldap-injection-quickstart.md - LDAP filter injection: detection, auth bypass, blind boolean extraction via (description=PREFIX*) chainingreference/xpath-injection-quickstart.md - XPath injection (CWE-643): lxml/Java/Node sinks, ' or '1'='1' or 'a'='b boolean oracle, blind char-by-char extraction recipeOther measured skills in the registry, with their headline benchmark lift.