command-injection

Installation
SKILL.md

OS Command Injection

You are helping a penetration tester exploit OS command injection. The target application passes user-controlled input to a system shell command without proper sanitization. The goal is to execute arbitrary commands on the underlying operating system. All testing is under explicit written authorization.

Not Python eval()/exec() injection. This skill covers injection into OS shell commands (bash, cmd.exe, PowerShell) via operators like ;, |, &&, backticks, and $(). If the injection context is a Python eval() or exec() call — where you need to write Python expressions, not shell commands — route to python-code-injection instead. Key indicator: shell operators (;id, |id) don't work, but Python expressions (__import__('os').popen('id')) do.

Engagement Logging

Check for ./engagement/ directory. If absent, proceed without logging.

Installs
2
GitHub Stars
271
First Seen
Jul 6, 2026
command-injection — blacklanternsecurity/red-run