Agent skill

Trace Injection Dataflows

by cyberful in cyberful/cyberful

Trace and test untrusted data through SQL, NoSQL, LDAP, XPath, XML, shell, process, template, expression-language, code-evaluation, log, spreadsheet, mail, header, and browser interpreters.

AGPL-3.0Auto-check passedDatabases

Install Trace Injection Dataflows

skills CLI
$ npx skills add cyberful/cyberful --skill trace-injection-dataflows -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cyberful/cyberful trace-injection-dataflows --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cyberful/cyberful.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cyberful/builtin/skills/trace-injection-dataflows .claude/skills/trace-injection-dataflows && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
trace-injection-dataflows
GitHub stars
135
Token cost
~1.1k tokens
SKILL.md length
357 words
Files
5 (incl. references)
Skills in repo
85
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Trace and test untrusted data through SQL, NoSQL, LDAP, XPath, XML, shell, process, template, expression-language, code-evaluation, log, spreadsheet, mail, header, and browser interpreters.

  • Injection vulnerability research
  • SKILL.md covers Define source and sink semantics, Prove control dominance, Test minimally and Handle parser differentials, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Parser-confusion analysis

What it does

Trace Injection Dataflows is an agent skill from cyberful/cyberful. Trace and test untrusted data through SQL, NoSQL, LDAP, XPath, XML, shell, process, template, expression-language, code-evaluation, log, spreadsheet, mail, header, and browser interpreters. Use for injection vulnerability research, taint analysis, source review, parser-confusion analysis, sanitizer validation, or proving whether data reaches an executable or structurally significant sink.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `agents/openai.yaml`, `references/field-heuristics.md` and `references/interpreter-catalog.md`).

It sits in Databases, covering NoSQL databases, Excel spreadsheets and Static analysis and SAST. It works with SQL. The repository describes itself as: Cyberful is an open-source AI Red Team for discovering, exploiting, verifying, and remediating vulnerabilities. The licence is AGPL-3.0.

When your agent uses it

  • Injection vulnerability research
  • Parser-confusion analysis
  • Sanitizer validation
  • Proving whether data reaches an executable

Example prompts

  • “/trace-injection-dataflows”

What it can do on your machine

Read from SKILL.md and the folder at commit ec598a6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cheatsheetseries.owasp.org
    • cwe.mitre.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Trace Injection Dataflows loads about 1.1k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 357 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cyberful/cyberful at commit ec598a6, republished under its AGPL-3.0 licence (© cyberful). 357 words, ~1,056 tokens.

Download SKILL.mdSave it as .claude/skills/trace-injection-dataflows/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
trace-injection-dataflows
description
Trace and test untrusted data through SQL, NoSQL, LDAP, XPath, XML, shell, process, template, expression-language, code-evaluation, log, spreadsheet, mail, header, and browser interpreters. Use for injection vulnerability research, taint analysis, source review, parser-confusion analysis, sanitizer validation, or proving whether data reaches an executable or structurally significant sink.
metadata.domain
application-security
metadata.subdomain
injection-dataflows
metadata.triggers
injection dataflow, source to sink trace, taint analysis, sanitizer validation, second-order injection, interpreter boundary
metadata.tags
injection, taint-analysis, source-to-sink, sanitization, parser-differential, interpreter

Trace Injection Dataflows

Injection exists when attacker-influenced data changes structure or execution in an interpreter. Validation failure without interpreter influence is not sufficient.

Define source and sink semantics

Identify source provenance, attacker capability, encoding, parser, transformations, storage, trust changes, and the exact interpreter grammar at the sink. Read references/interpreter-catalog.md for sink-specific invariants.

Trace both forward from sources and backward from sinks:

source -> decode/canonicalize -> validate -> transform -> store -> retrieve -> encode/parameterize -> interpreter -> effect

Include second-order data, batch jobs, logs later parsed by tools, templates stored then rendered, queue messages, imported files, plugin metadata, and administrator-facing workflows.

Prove control dominance

Determine whether parameterization, safe API, allowlist, contextual encoding, typed builder, sandbox, or structural separation dominates every reachable path. A sanitizer is valid only for the exact interpreter context and after the final decoding or canonicalization step.

Read references/taint-proof.md for audit and evidence rules. Use references/field-heuristics.md for multi-parser, second-order, identifier, and blind-flow differentials.

Test minimally

Use syntax-neutral markers, paired valid/invalid structures, type changes, or safe expression effects before any high-impact payload. Observe query plan, parsed structure, rendered context, child-process argv, log fields, or other ground truth when available. Avoid extracting real data or executing destructive commands.

For blind claims, require a discriminating timing or OAST control tied to a unique token and authorized infrastructure. A generic error, status change, reflection, or latency spike is a lead.

Show full SKILL.md (136 more words)Show less

Handle parser differentials

Compare client, gateway, framework, application, library, database, shell, template, and downstream parser behavior for duplicate fields, encodings, Unicode, nulls, separators, comments, quoting, numeric forms, media types, and normalization. Validate after canonicalization and before interpretation.

Audit remediation

Prefer structural APIs: prepared statements, typed query builders, argument arrays, fixed templates, safe renderers, schema-bound serialization, structured logging, and explicit protocol libraries. Allowlists constrain identifiers or operations that cannot be parameterized. Escaping is context-specific and usually a last boundary control.

Confirmation standard

Record source, full data path, interpreter and grammar context, failed control, safe control case, observable structural or execution effect, attacker capability, and affected authority. Scope systemic findings to shared unsafe helpers only after proving their callers and contexts.

Authoritative anchors

© cyberful, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in cyberful/builtin/skills/trace-injection-dataflows of cyberful/cyberful.

  • SKILL.md
  • agents/openai.yaml
  • references/field-heuristics.md
  • references/interpreter-catalog.md
  • references/taint-proof.md

Open the folder on GitHubat commit ec598a6

Compare with similar skills

Trace Injection Dataflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Trace Injection Dataflows compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Trace Injection Dataflows this skillcyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.0
Mindsdb MCP SkillLeoYeAI/openclaw-master-skills2.2k—~2.5kAutomated safety check: PassMIT
Azure Storagemicrosoft/GitHub-Copilot-for-Azure2552 repos~1.3kAutomated safety check: PassMIT
Database Architecture InterviewerPrepLabsAI/InterviewMentor112—~2.4kAutomated safety check: PassMIT
Injection Vulnszhaji2333/CkSKILLS113—~579Automated safety check: PassMIT
Database MigrationDokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI507—~227Automated safety check: PassCustom licence

Similar skills

  • Mindsdb MCP Skill

    LeoYeAI/openclaw-master-skills

    MindsDB MCP服务器交互技能,用于通过自然语言查询和操作200+企业级数据源。当用户需要查询数据库、分析数据、创建AI模型、连接数据源(MySQL、PostgreSQL、MongoDB、Excel、CSV、Gmail、Slack等)、执行SQL查询、进行数据预测、构建知识库(RAG)、智能问答、文档检索或任何与数据库交互的任务时使用此技能。即使没有明确提到MindsDB,只要涉及数据库操…

    2.2k GitHub stars~2.5k tokensUpdated 2 mo ago
    DatabasesAuto-check passed
  • Azure Storage

    microsoft/GitHub-Copilot-for-Azure

    Official

    Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.

    255 GitHub starsUsed in 2 repos~1.3k tokens
    DatabasesAuto-check passed
  • Database Architecture Interviewer

    PrepLabsAI/InterviewMentor

    A Principal Database Engineer interviewer. An agent skill from PrepLabsAI/InterviewMentor.

    112 GitHub stars~2.4k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Injection Vulns

    zhaji2333/CkSKILLS

    当发现参数拼接SQL、动态排序/筛选、JSON查询条件可控、模板渲染、命令执行点、搜索/统计/自动补全接口时调用,进行SQL/NoSQL/命令/SSTI/表达式注入的深度挖掘。命中场景:搜索框、排序参数、登录绕过、导出条件、文件名参数、模板/报表生成、爬虫URL参数。

    113 GitHub stars~579 tokensUpdated 23 days ago
    DatabasesAuto-check passed
  • Database Migration

    Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI

    MASTER DB: Zero-Downtime, Schema Design (3NF), SQL/NoSQL. An agent skill from Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI.

    507 GitHub stars~227 tokensUpdated 3 mo ago
    DatabasesAuto-check passed
  • Ddia Systems

    wondelai/skills

    Design data systems by understanding storage engines, replication, partitioning, transactions, and consistency models.

    2.4k GitHub stars~4.2k tokensUpdated 27 days ago
    DatabasesAuto-check passed

More from cyberful/cyberful

All 85 skills in this repo
  • Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence.

    135 GitHub stars~649 tokensUpdated 1 mo ago
    Auto-check passed
  • Audit Kubernetes admission and policy-as-code enforcement against local workload manifests, exception paths, namespace scope, and deployment evidence.

    135 GitHub stars~610 tokensUpdated 1 mo ago
    Auto-check passed
  • Audit PCI DSS penetration-test methodology, scope, internal and external reports, segmentation results, tester independence, remediation, retesting, retention, and multi-tenant support evidence.

    135 GitHub stars~1k tokensUpdated 1 mo ago
    Auto-check passed
  • Operate Content Discovery

    cyberful/cyberful

    Design and interpret advanced content discovery with ffuf and complementary web fuzzers.

    135 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Operate Network Recon

    cyberful/cyberful

    Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up.

    135 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Operate Sast Toolchain

    cyberful/cyberful

    Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits.

    135 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Trace Injection Dataflows

What does Trace Injection Dataflows do?

Trace and test untrusted data through SQL, NoSQL, LDAP, XPath, XML, shell, process, template, expression-language, code-evaluation, log, spreadsheet, mail, header, and browser interpreters. Trace Injection Dataflows is an agent skill from cyberful/cyberful. Trace and test untrusted data through SQL, NoSQL, LDAP, XPath, XML, shell, process, template, expression-language, code-evaluation, log, spreadsheet, mail, header, and browser interpreters.

When should I use Trace Injection Dataflows?

Trace Injection Dataflows fits situations like: injection vulnerability research; parser-confusion analysis; sanitizer validation; proving whether data reaches an executable.

How do I install Trace Injection Dataflows in Claude Code?

Run `npx skills add cyberful/cyberful --skill trace-injection-dataflows -a claude-code`. Or copy the skill folder (cyberful/builtin/skills/trace-injection-dataflows in cyberful/cyberful) into .claude/skills/trace-injection-dataflows in your project. Claude Code loads it when a task matches its description.

How do I install Trace Injection Dataflows in Codex?

Run `npx skills add cyberful/cyberful --skill trace-injection-dataflows -a codex`. Or copy the skill folder (cyberful/builtin/skills/trace-injection-dataflows in cyberful/cyberful) into .agents/skills/trace-injection-dataflows in your project. Codex loads it when a task matches its description.

Can I use Trace Injection Dataflows in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cyberful/cyberful --skill trace-injection-dataflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/trace-injection-dataflows, .gemini/skills/trace-injection-dataflows, .github/skills/trace-injection-dataflows and .opencode/skills/trace-injection-dataflows in your project.

What does Trace Injection Dataflows need to run?

SKILL.md names no scripts, command-line tools or credentials: Trace Injection Dataflows is instructions for the agent only.

Does Trace Injection Dataflows access the network?

SKILL.md names 2 domains. As links in the text: cheatsheetseries.owasp.org and cwe.mitre.org. This is read from the text; nothing was executed.

Is Trace Injection Dataflows safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Trace Injection Dataflows use?

Trace Injection Dataflows is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Trace Injection Dataflows use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Trace Injection Dataflows?

Skills that share tags, products or a category with Trace Injection Dataflows: Mindsdb MCP Skill (LeoYeAI/openclaw-master-skills, 2.2k stars), Azure Storage (microsoft/GitHub-Copilot-for-Azure, 255 stars), Database Architecture Interviewer (PrepLabsAI/InterviewMentor, 112 stars) and Injection Vulns (zhaji2333/CkSKILLS, 113 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Trace Injection Dataflows?

cyberful (a GitHub organization) maintains it in cyberful/cyberful, which has 135 GitHub stars. The repository holds 85 skills in this directory. The repository was last updated on August 24, 2026.

Source: cyberful/cyberful on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.