Agent skill

Injection Checking

by yaklang in yaklang/hack-skills

Entry P1 category router for injection testing. An agent skill from yaklang/hack-skills.

MITAuto-check passedSecurity

Install Injection Checking

skills CLI
$ npx skills add yaklang/hack-skills --skill injection-checking -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yaklang/hack-skills injection-checking --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/injection-checking .claude/skills/injection-checking && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
injection-checking
GitHub stars
2.4k
Token cost
~570 tokens
SKILL.md length
190 words
Files
2
Skills in repo
26
Repo updated
First seen
Licence
MIT

At a glance

Entry P1 category router for injection testing. An agent skill from yaklang/hack-skills.

  • Works in 3 steps: First identify the final sink of the input → Then choose the topic skill that best… → Small payload samples and quick triage…
  • Routing between XSS
  • SKILL.md covers When to Use, Skill Map, Recommended Flow and Related Categories
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Injection Checking is an agent skill from yaklang/hack-skills. Entry P1 category router for injection testing. Use when routing between XSS, SQLi, SSRF, XXE, SSTI, command injection, and NoSQL injection workflows based on how attacker-controlled input is consumed.

Its SKILL.md is about 570 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `EXTRA_INJECTION_TYPES.md`).

It sits in Security, covering Web application vulnerabilities and NoSQL databases. The repository describes itself as: Helping AI Agent become an awesome practical hacker! The licence is MIT.

When your agent uses it

  • Routing between XSS
  • Command injection
  • NoSQL injection workflows based on how attacker-controlled input is consumed

Example prompts

  • “/injection-checking”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. First identify the final sink of the input
  2. Then choose the topic skill that best matches that interpreter
  3. Small payload samples and quick triage are merged into each main skill; no extra payload router is needed

What it can do on your machine

Read from SKILL.md and the folder at commit 6fbf0bc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Injection Checking loads about 570 tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 190 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~570

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yaklang/hack-skills at commit 6fbf0bc, republished under its MIT licence (© yaklang). 190 words, ~570 tokens.

Download SKILL.mdSave it as .claude/skills/injection-checking/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
injection-checking
description
Entry P1 category router for injection testing. Use when routing between XSS, SQLi, SSRF, XXE, SSTI, command injection, and NoSQL injection workflows based on how attacker-controlled input is consumed.

Injection Testing Router

This is the routing entry point when input reaches a dangerous interpreter or execution environment.

After confirming this is an injection-class issue, use it to decide whether it is mainly browser context, database, template engine, server-side requests, XML parsing, or system commands.

When to Use

  • Input reaches HTML, JS, SQL, templates, URL fetchers, XML parsers, or shell
  • You have not yet decided whether to start with XSS, SQLi, SSRF, XXE, SSTI, CMDi, or NoSQL
  • You need to choose the correct deep-topic skill based on input flow

Skill Map

  1. First identify the final sink of the input
  2. Then choose the topic skill that best matches that interpreter
  3. Small payload samples and quick triage are merged into each main skill; no extra payload router is needed

© yaklang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/injection-checking of yaklang/hack-skills.

  • SKILL.md
  • EXTRA_INJECTION_TYPES.md

Open the folder on GitHubat commit 6fbf0bc

Compare with similar skills

Injection Checking next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Injection Checking compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Injection Checking this skillyaklang/hack-skills2.4k—~570Automated safety check: PassMIT
WafTheDecipherist/claude-code-mastery-project-starter-kit338—~1.4kAutomated safety check: PassMIT
Java Injection Auditwgpsec/AboutSecurity1.8k—~1.1kAutomated safety check: PassNone
Php Injection Auditwgpsec/AboutSecurity1.8k—~965Automated safety check: PassNone
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0

Similar skills

  • Waf

    TheDecipherist/claude-code-mastery-project-starter-kit

    Web Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic.

    338 GitHub stars~1.4k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Java Injection Audit

    wgpsec/AboutSecurity

    Java 源码注入类漏洞审计。当在 Java 白盒审计中需要检测注入类漏洞时触发. An agent skill from wgpsec/AboutSecurity.

    1.8k GitHub stars~1.1k tokensUpdated 4 days ago
    DatabasesAuto-check passed
  • Php Injection Audit

    wgpsec/AboutSecurity

    PHP 源码注入类漏洞审计。当在 PHP 白盒审计中需要检测注入类漏洞时触发. An agent skill from wgpsec/AboutSecurity.

    1.8k GitHub stars~965 tokensUpdated 4 days ago
    DatabasesAuto-check passed
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes

More from yaklang/hack-skills

All 26 skills in this repo
  • Anti Debugging Techniques

    yaklang/hack-skills

    Anti-debugging detection and bypass playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~3.4k tokensUpdated 24 days ago
    Auto-check passed
  • API Auth And JWT Abuse

    yaklang/hack-skills

    API authentication and JWT abuse playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~567 tokensUpdated 24 days ago
    Auto-check passed
  • API Authorization And Bola

    yaklang/hack-skills

    API authorization and BOLA testing playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~449 tokensUpdated 24 days ago
    Auto-check passed
  • API Recon And Docs

    yaklang/hack-skills

    API reconnaissance and documentation review playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~456 tokensUpdated 24 days ago
    Auto-check passed
  • Attack Surface Mapping

    yaklang/hack-skills

    Draw a testable attack surface from one authorized target URL or one application.

    2.4k GitHub stars~2.6k tokensUpdated 24 days ago
    Auto-check passed
  • Classical Cipher Analysis

    yaklang/hack-skills

    Classical cipher analysis playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~4.8k tokensUpdated 24 days ago
    Auto-check passed

Categories

Questions about Injection Checking

What does Injection Checking do?

Entry P1 category router for injection testing. An agent skill from yaklang/hack-skills. Injection Checking is an agent skill from yaklang/hack-skills. Entry P1 category router for injection testing.

When should I use Injection Checking?

Injection Checking fits situations like: routing between XSS; command injection; noSQL injection workflows based on how attacker-controlled input is consumed.

How do I install Injection Checking in Claude Code?

Run `npx skills add yaklang/hack-skills --skill injection-checking -a claude-code`. Or copy the skill folder (skills/injection-checking in yaklang/hack-skills) into .claude/skills/injection-checking in your project. Claude Code loads it when a task matches its description.

How do I install Injection Checking in Codex?

Run `npx skills add yaklang/hack-skills --skill injection-checking -a codex`. Or copy the skill folder (skills/injection-checking in yaklang/hack-skills) into .agents/skills/injection-checking in your project. Codex loads it when a task matches its description.

Can I use Injection Checking in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaklang/hack-skills --skill injection-checking -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/injection-checking, .gemini/skills/injection-checking, .github/skills/injection-checking and .opencode/skills/injection-checking in your project.

What does Injection Checking need to run?

SKILL.md names no scripts, command-line tools or credentials: Injection Checking is instructions for the agent only.

Does Injection Checking access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Injection Checking safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Injection Checking use?

Injection Checking is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Injection Checking use?

About 570 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Injection Checking?

Skills that share tags, products or a category with Injection Checking: Waf (TheDecipherist/claude-code-mastery-project-starter-kit, 338 stars), Java Injection Audit (wgpsec/AboutSecurity, 1.8k stars), Php Injection Audit (wgpsec/AboutSecurity, 1.8k stars) and Security And Hardening (penpot/penpot, 61k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Injection Checking?

yaklang (a GitHub organization) maintains it in yaklang/hack-skills, which has 2,394 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on September 13, 2026.

Source: yaklang/hack-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.