Hunt NoSQL Injection — MongoDB operator injection ($where, $regex, $gt, $ne), CouchDB, Redis command injection, auth bypass via NoSQLi, data dump. Use when target uses MongoDB/Mongoose, CouchDB, Redis, or shows NoSQL error messages.
76
95%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Security
2 findings: 2 critical severity. Installing this skill is not recommended: please review these findings carefully if you do intend to do so.
Detected a prompt injection in the skill instructions. The skill contains hidden or deceptive instructions that fall outside its stated purpose and attempt to override the agent’s safety guidelines or intended behavior.
This skill is an explicit offensive how-to for NoSQL injection, providing step-by-step commands and techniques for auth bypass, data exfiltration, and remote command injection (Redis/SSRF), i.e., clearly malicious guidance.
Detected high-risk code patterns in the skill content — including its prompts, tool definitions, and resources — such as data exfiltration, backdoors, remote code execution, credential theft, system compromise, supply chain attacks, and obfuscation techniques.
The document intentionally provides concrete, executable attack payloads and runtime commands (curl JSON bodies, $where JS payloads, Redis gopher/SLAVEOF sequences, nosqlmap usage) to bypass authentication, execute arbitrary JS in the DB process, deploy/configure Redis for a webshell, and exfiltrate data, demonstrating clear malicious intent and viable execution mechanisms.
58017df
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.