Pentest injection engine
Skill 0x-Professor/Agent-Skills-Hub/skills/pentest-injection-engine
Public skill pack for AI coding/automation/penetration-testing agents.
npx -y skills add 0x-Professor/Agent-Skills-Hub --skill pentest-injection-engineAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 10 stars10 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Systematically test authorized targets for SQL, XSS, SSTI, XXE, command, and request-smuggling injection classes.
SKILL.md
1.3 KB, as published. Nobody here has run it
Pentest Injection Engine
Stage
- PTES: 5
- MITRE: T1190, T1059
Objective
Validate injection exploitability and capture payload-level evidence.
Required Workflow
- Validate scope before any active action and reject out-of-scope targets.
- Run only authorized checks aligned to PTES, OWASP WSTG, NIST SP 800-115, and MITRE ATT&CK.
- Write findings in canonical finding_schema format with reproducible PoC notes.
- Honor dry-run mode and require explicit --i-have-authorization for live execution.
- Export deterministic artifacts for downstream skill consumption.
Execution
python skills/pentest-injection-engine/scripts/injection_engine.py --scope scope.json --target <target> --input <path> --output <path> --format json --dry-run
Outputs
injection-findings.jsonxss-payloads-that-fired.jsoninjection-report.json
References
references/tools.mdskills/autonomous-pentester/shared/scope_schema.jsonskills/autonomous-pentester/shared/finding_schema.json
Legal and Ethical Notice
WARNING AUTHORIZED USE ONLY
This skill executes real security testing tools against live targets.
Use only with written authorization.