exploiting-nosql-injection-vulnerabilities

mukul975/exploiting-nosql-injection-vulnerabilities · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate authentication bypass, data extraction, and unauthorized access risks.

SKILL.md

Files

This skill is a package of 8 files. Install with the command above, or download the folder.

Related

  1. exploiting-websocket-vulnerabilities · mukul975 bundle
    Test WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments.
    24.6k
    repo stars
  2. cross-site-scripting-xss-complete-deep-dive · shulkwisec bundle
    Provides a complete deep-dive into Cross-Site Scripting (XSS) with exact payloads and bypass techniques for every PortSwigger lab variant, from apprentice to expert level.
    21
    repo stars
  3. burpsuite-project-parser · trailofbits bundle
    Searches and extracts data from Burp Suite project files (.burp) using the burpsuite-project-file-parser extension, enabling regex searches on response headers and bodies, extraction of security audit findings, and analysis of proxy history and site map data.
    6k
    repo stars
  4. pentest · tinh2
    Performs a static-analysis penetration test to find exploitable vulnerabilities, providing proof-of-concept payloads and fixes. Covers injection, XSS, authentication bypass, authorization flaws, path traversal, command injection, CSRF, SSRF, hardcoded secrets, and insecure deserialization, with a full attack surface.
    13
    repo stars
  5. csrf · shulkwisec
    Detect and exploit Cross-Site Request Forgery vulnerabilities by testing for missing or predictable CSRF tokens, absent SameSite cookie attributes, and JSON endpoints accepting text/plain Content-Type, with payloads and bypass techniques for security testing.
    21
    repo stars
  6. bola-idor · shulkwisec
    Detect and exploit Broken Object Level Authorization (BOLA) and Insecure Direct Object Reference (IDOR) vulnerabilities in APIs and web applications.
    21
    repo stars

Frequently asked questions

How do I install the exploiting-nosql-injection-vulnerabilities skill?

Run npx skillmds add mukul975/exploiting-nosql-injection-vulnerabilities in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the exploiting-nosql-injection-vulnerabilities skill do?

Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate authentication bypass, data extraction, and unauthorized access risks. It is listed under Security, Penetration Testing on SkillMD.

Is exploiting-nosql-injection-vulnerabilities safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: WARNING. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with exploiting-nosql-injection-vulnerabilities?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is exploiting-nosql-injection-vulnerabilities free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published exploiting-nosql-injection-vulnerabilities?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.