hunt-nosqli

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous curl commands intended for vulnerability scanning against a user-defined $TARGET variable. It also includes local shell commands for validating the skill's own structure.
  • [EXTERNAL_DOWNLOADS]: Includes instructions to install nosqlmap using pip3. nosqlmap is a well-known open-source tool for automating NoSQL injection testing.
  • [REMOTE_CODE_EXECUTION]: Documents methods for achieving remote code execution on a target system through $where JavaScript injection in MongoDB or configuration manipulation in Redis via SSRF. These are described as security testing objectives rather than malicious actions performed by the skill itself.
  • [DATA_EXFILTRATION]: Describes techniques for extracting data from a target database, such as character-by-character enumeration using regex or time-based blind injection. These actions are scoped to the intended security auditing use case.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:47 PM
Security Audit — agent-trust-hub — hunt-nosqli